12 versions
Sigma Forms history.
Every release of Sigma Forms is archived here with its changelog, file size, and security scan result. Use the archive to roll back to a stable release or audit what changed between updates.
12 of 12 releases scanned clean
v1.4.12Latest
August 26, 2026576.2 KBScanned
Other
- ### Security
- File upload fields now ignore values that did not arrive as a real upload
- Stored upload URLs are deleted only when they resolve to a file inside the uploads directory
Fixed
- an arbitrary file deletion vulnerability in the submission delete handlers (CVE-2026-78657)
August 9, 2026584.7 KBScanned
Added
- "Transition" form theme - a card driven quiz/funnel style with selectable image cards, animated states and a multi-step progress bar
- Field label images on every field type, with the image positioned above, below, left or right of the label text
- Label image sizing by percentage of the field (stays proportional on any screen) or by fixed pixels, plus an optional height and a Full Width option
- Drag to resize label images directly in the form preview - edge handles for width and height, corner handle for both, hold Shift to keep the aspect ratio
- Built in image cropper for label and option images, using the WordPress media cropper. Crops always start from the original upload and are saved as a new attachment, so the source file is never modified
- Per option images for Radio, Checkbox and Dropdown fields, with a shared position and size per field. Dropdowns with images render an image capable listbox while keeping the native select for validation and conditional logic
- "Show Country Flag Icons" toggle for Country and International Phone fields, to show or hide flag icons on the frontend
- Separate "Show Field Label Text" and "Show Field Label Image" toggles, so the text and the image can be hidden independently
- Automatic retention policy for form view logs - set how many days of view history to keep (default 60) from Settings > Advanced > Data Cleanup, with a live count of entries queued for deletion
Improved
- View log cleanup runs in small batches inside a time budget, so clearing a large backlog never holds a long database lock or exceeds the PHP time limit
v1.4.7Unavailable
July 15, 2026552.5 KBScanned
= Added =
* CC and BCC email fields for form submission notifications in global settings and per-form email overrides
* Support for multiple email addresses (comma-separated) in To, CC, and BCC fields
v1.4.6Unavailable
July 7, 2026551.4 KBScanned
Fixed
- critical security vulnerability that allowed unauthenticated arbitrary file upload and remote code execution via public form file fields
v1.4.4Unavailable
May 25, 2026550.5 KBScanned
= Updated =
* Made compatible with WordPress version 7.0
= Improved =
* Button icon alignment across admin screens
v1.4.1Unavailable
May 4, 2026523.3 KBScanned
= Added =
* Export/Import Settings feature in Advanced Settings tab
* Export all SigmaForms settings to JSON file with timestamp
* Import settings from previously exported JSON file with automatic saving
* Settings validation and sanitization on import for security
= Fixed =
* Plugins list "Settings" link now opens SigmaForms Settings (`sigmaforms-settings`) instead of the Forms list
Why archive
Sometimes the latest release isn't the one you need. The archive lets you pin Sigma Forms to a known-good version, or roll back while a bug is investigated. Every release stays scanned and reachable.