← Terug naar overzicht

The Sigma Forms Pro plugin for WordPress contains a critical Remote Code Execution vulnerability affecting all versions up to and including 1.4.5. The flaw exists in the handle_form_submission function, which dynamically grants the unfiltered_upload capability to all users during form submissions and bypasses MIME type validation when allowed_file_types is not configured. This allows unauthenticated attackers to upload arbitrary files and execute code on the server. The vulnerability is made immediately exploitable upon installation because several default pre-built templates, including Job Application, Support Ticket, and Wholesale Application, include file upload fields with no file type restrictions by design. The combination of privilege escalation, MIME bypass, and insecure defaults makes this a critical, zero-authentication attack vector requiring urgent patching.

Affected products

  • Sigma Forms Pro plugin for WordPress (versions up to 1.4.5)

Related CVE's

  • CVE-2026-14494

Categories

  • Web Technologies
  • Zero-Day Vulnerabilities