VYPR

Sigma Forms Pro

by WordPress

CVEs (1)

  • CVE-2026-14494CriAug 29, 2026
    risk 0.64cvss 9.8epss

    The Sigma Forms Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.4.5 via the handle_form_submission function. This is due to the plugin dynamically granting the unfiltered_upload capability to all users during form…