WORDPRESS · AUGUST 2026 · EARLY WARNING

Sigma Forms Pro WordPress Plugin Vulnerable to Remote Code Execution

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity
CRITICAL
CVSS
9.8
Affected component
sigma forms pro (wordpress)
Patched version
Not yet available
CVE-2026-14494

The Sigma Forms Pro plugin for WordPress is reportedly vulnerable to Remote Code Execution in all versions up to, and including, 1.4.5.

What happened

An early warning has been issued regarding a critical vulnerability in the Sigma Forms Pro plugin for WordPress. This vulnerability, tracked as CVE-2026-14494, allows for Remote Code Execution due to the plugin dynamically granting the unfiltered_upload capability to all users during form submissions and bypassing MIME type validation when allowed_file_types is not configured. The vulnerability affects all versions of the plugin up to, and including, 1.4.5. The issue is under investigation and no exploitation in the wild has been confirmed at this time.

Users of the Sigma Forms Pro plugin should immediately assess whether they are running an affected version. The vulnerability is severe, with a CVSS score of 9.8, indicating a critical level of risk. It is crucial to take immediate action to mitigate potential risks.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If sigma forms pro is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

If you are using the Sigma Forms Pro plugin for WordPress and your version is 1.4.5 or earlier, you are affected.

What should I do right now?

Check your Sigma Forms Pro plugin version. If it is 1.4.5 or earlier, consider disabling the plugin and monitor the NVD page for updates on a patched version.

When will a fix be available?

No official fix has been published yet. Monitor the sources below for updates.

Sources

Join the 0Day waitlist →

← Back to all threats