CVE-2026-14494: Sigma Forms Pro <= 1.4.5 - Unauthenticated Unauthenticated Arbitrary File Upload Leading to Remote Code Execution via Pre-built Template File Upload Field

Published Aug 29, 2026
·
Updated

The Sigma Forms Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.4.5 via the handleformsubmission function. This is due to the plugin dynamically granting the unfilteredupload capability to all users during form submissions and bypassing MIME type validation when allowedfiletypes is not configured. This makes it possible for unauthenticated attackers to execute code on the server. Several default pre-built templates including Job Application, Support Ticket, and Wholesale Application have file upload fields with no file type restrictions configured by design, making this vulnerability immediately exploitable upon installation.

Affected Software

1 affected component
Sigma Forms Sigma Forms Pro (WordPress plugin)<=1.4.5

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Sigma Forms Pro to a version that resolves this vulnerability.

    Fixed in 1.4.5
  2. Configuration

    Configure file upload type restrictions for the pre-built templates (Job Application, Support Ticket, Wholesale Application) so the file upload field has file type restrictions enabled; this addresses the condition where MIME type validation is bypassed when allowed_file_types is not configured.

    Sigma Forms Pro (WordPress plugin) allowed_file_types = configured
  3. Configuration

    Ensure the plugin does not dynamically grant the unfiltered_upload capability to all users during form submissions; this prevents unauthenticated attackers from uploading executable files via handle_form_submission.

    Sigma Forms Pro (WordPress plugin) unfiltered_upload capability during form submissions = not granted to all users
  4. Compensating control

    Block/limit unauthenticated access to the affected form submission endpoints for Sigma Forms Pro (e.g., via network/WAF/ACL) to reduce exposure until the plugin is remediated.

Event History

Aug 29, 2026
CVE Published
via MITRE·11:30 AM
Data Sourced
via MITRE·11:30 AM
DescriptionSeverityWeakness

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203