Sigma Forms Pro WordPress Plugin Vulnerable to Remote Code Execution
- Severity
- CRITICAL
- CVSS
- 9.8
- Affected component
- sigma forms pro (wordpress)
- Patched version
- Not yet available
The Sigma Forms Pro plugin for WordPress is reportedly vulnerable to Remote Code Execution in all versions up to, and including, 1.4.5.
What happened
An early warning has been issued regarding a critical vulnerability in the Sigma Forms Pro plugin for WordPress. This vulnerability, tracked as CVE-2026-14494, allows for Remote Code Execution due to the plugin dynamically granting the unfiltered_upload capability to all users during form submissions and bypassing MIME type validation when allowed_file_types is not configured. The vulnerability affects all versions of the plugin up to, and including, 1.4.5. The issue is under investigation and no exploitation in the wild has been confirmed at this time.
Users of the Sigma Forms Pro plugin should immediately assess whether they are running an affected version. The vulnerability is severe, with a CVSS score of 9.8, indicating a critical level of risk. It is crucial to take immediate action to mitigate potential risks.
What to do about it
- Monitor the NVD page for CVE-2026-14494 for updates on a patched version.
- If you are using Sigma Forms Pro, check your plugin version and compare it against the affected versions listed.
- As a precautionary measure, consider disabling the Sigma Forms Pro plugin until a patched version is available.
- Stay informed by consulting the primary sources provided for the latest information on this vulnerability.
How 0Day would have caught this
sigma forms pro is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
If you are using the Sigma Forms Pro plugin for WordPress and your version is 1.4.5 or earlier, you are affected.
What should I do right now?
Check your Sigma Forms Pro plugin version. If it is 1.4.5 or earlier, consider disabling the plugin and monitor the NVD page for updates on a patched version.
When will a fix be available?
No official fix has been published yet. Monitor the sources below for updates.