{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3awordpresssigma_forms_pro/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:wordpress:sigma_forms_pro:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-14494"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Sigma Forms Pro (\u003c= 1.4.5)"],"_cs_severities":["critical"],"_cs_tags":["web-application-vulnerability","wordpress","rce","file-upload"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe Sigma Forms Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.4.5. The vulnerability resides within the handle_form_submission function, which fails to correctly enforce security constraints during form processing. Specifically, the plugin dynamically grants the unfiltered_upload capability to users during form submissions and lacks mandatory MIME type validation when the allowed_file_types configuration is omitted.\u003c/p\u003e\n\u003cp\u003eBecause several default pre-built templates, such as Job Application, Support Ticket, and Wholesale Application, are shipped without file type restrictions, the plugin is susceptible to exploitation in its default configuration immediately upon installation. Unauthenticated attackers can leverage this flaw to upload malicious scripts (e.g., PHP web shells) to the web server, achieving remote code execution. This vulnerability is rated as critical with a CVSS v3.1 base score of 9.8, representing a significant risk of total server compromise for any WordPress installation utilizing the affected plugin versions.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to execute arbitrary code on the underlying web server. This can lead to full site takeover, unauthorized access to sensitive database information, data exfiltration, or the establishment of persistent backdoors within the WordPress environment. Organizations using the affected versions in production are at high risk of compromise.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized, concrete actions for security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate Sigma Forms Pro to the latest available version beyond 1.4.5 immediately to patch CVE-2026-14494.\u003c/li\u003e\n\u003cli\u003eIf an update is unavailable, audit all existing form templates in the Sigma Forms Pro dashboard and enforce strict file type validation (allowed_file_types) on every form containing a file upload field.\u003c/li\u003e\n\u003cli\u003eDisable any pre-built templates (Job Application, Support Ticket, Wholesale Application) that utilize file upload fields until validation is explicitly configured.\u003c/li\u003e\n\u003cli\u003eDeploy web application firewall (WAF) rules to detect and block file upload requests containing suspicious extensions (e.g., .php, .phtml, .php5) targeted at WordPress plugin directories.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-29T13:38:43Z","date_published":"2026-08-29T13:38:43Z","id":"https://feed.craftedsignal.io/briefs/2026-08-sigma-forms-rce/","summary":"The Sigma Forms Pro plugin for WordPress is vulnerable to unauthenticated remote code execution due to improper validation of file uploads and insecure capability management within the handle_form_submission function.","title":"Remote Code Execution in Sigma Forms Pro Plugin for WordPress","url":"https://feed.craftedsignal.io/briefs/2026-08-sigma-forms-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:wordpress:sigma_forms_pro:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}