CRITICAL 9.8 CVE-2026-14494 Published 29 Aug 2026

WordPress Sigma Forms Pro RCE Bug

Worried this affects one of your servers?

The Sigma Forms Pro plugin for WordPress is vulnerable to Remote Code Execution (RCE) in versions up to 1.4.5.

This is due to the plugin dynamically granting the unfiltered_upload capability to all users during form submissions and bypassing MIME type validation when allowed_file_types is not configured.

Several default pre-built templates, including Job Application, Support Ticket, and Wholesale Application, have file upload fields with no file type restrictions configured by design, making this vulnerability immediately exploitable upon installation.

Reference: CVE-2026-14494 on NVD

← Back to Security News