Junglewise Threat Intelligence

CVE-2026-14494: Sigma Forms Pro Remote Code Execution via unfiltered upload

CVE-2026-14494 · Severity: critical · CVSS 9.8 · Published 2026-08-29

Vendors: BdThemes.

Executive brief

Sigma Forms Pro is a WordPress plugin used to create and manage web forms with file upload capabilities. A critical vulnerability allows unauthenticated attackers to upload and execute arbitrary code on the website by exploiting improper file type validation in the form submission handler. Several default form templates ship with no file restrictions, making the vulnerability exploitable immediately after plugin installation without any configuration changes.

Technical details

The vulnerability exists in the handle_form_submission function, which dynamically grants the unfiltered_upload capability to all users during form processing and fails to validate file types when the allowed_file_types setting is not configured. An unauthenticated attacker can exploit this by submitting a form with a malicious file (e.g., PHP shell) via one of the default pre-built form templates (Job Application, Support Ticket, Wholesale Application) that have file upload fields with no type restrictions by design. This allows arbitrary file uploads and code execution on the server. The vulnerability affects all versions up to and including 1.4.5.

Affected products

  • BdThemes Sigma Forms Pro up to and including 1.4.5

Timeline

  • 2026-08-29: disclosed

References