VYPR

SigmaForms Pro

by WordPress

CVEs (3)

  • CVE-2026-78657CriSep 2, 2026
    risk 0.64cvss 9.8epss 0.01

    The SigmaForms Pro – AI Generated Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_submission_files function in all versions up to, and including, 1.4.11. This makes it possible for unauthenticated…

  • CVE-2026-14494CriAug 29, 2026
    risk 0.64cvss 9.8epss 0.01

    The Sigma Forms Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.4.5 via the handle_form_submission function. This is due to the plugin dynamically granting the unfiltered_upload capability to all users during form…

  • CVE-2026-52705CriJun 17, 2026
    risk 0.59cvss 9.0epss 0.00

    Unauthenticated Arbitrary File Upload in SigmaForms Pro – AI Generated Forms <= 1.4.5 versions.