Bit Form <= 3.2.0 - Authenticated (Administrator+) SQL Injection via 'filterText' Parameter
medium
The Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder plugin for WordPress is vulnerable to generic SQL Injection via the 'data[queryCondition]' parameter in all versions up to, and including, 3.2.0 due to insufficient escaping on the user supplied parameter and lack of sufficie...
- CVSS:
- 6.5
- Affected:
- up to 3.2.0
- Fixed in:
- 3.2.1
- Disclosed:
- Aug 13, 2026
CVE-2026-16810 on NVD →
Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder < 3.1.4 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 3.1.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-leve...
- CVSS:
- 4.4
- Affected:
- up to 3.1.4
- Fixed in:
- 3.1.4
- Disclosed:
- Aug 1, 2026
CVE-2025-15669 on NVD →
Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder < 3.1.2 - Missing Authorization to Unauthenticated Unauthorized Form Submission
medium
The Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to 3.1.2 (exclusive). This makes it possible for unauthenticated attackers to submit forms that they...
- CVSS:
- 5.3
- Affected:
- up to 3.1.2
- Fixed in:
- 3.1.2
- Disclosed:
- Jul 30, 2026
CVE-2026-15054 on NVD →
Bit Form <= 3.1.0 - Unauthenticated Stored Cross-Site Scripting
high
The Bit Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an i...
- CVSS:
- 7.2
- Affected:
- up to 3.1.0
- Fixed in:
- 3.2.0
- Disclosed:
- Jul 27, 2026
CVE-2026-16573 on NVD →
Bit Form <= 3.1.1 - Authenticated (Subscriber+) Arbitrary File Deletion via '_old' Parameter
high
The Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the deleteFiles function in all versions up to, and including, 3.1.1 This makes it possible for authenticated attackers...
- CVSS:
- 7.1
- Affected:
- up to 3.1.1
- Fixed in:
- 3.1.2
- Disclosed:
- Jul 8, 2026
CVE-2026-14372 on NVD →
Bit Form <= 3.0.0 - Unauthenticated Arbitrary File Read
high
The Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.0.0. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can cont...
- CVSS:
- 7.5
- Affected:
- up to 3.0.0
- Fixed in:
- 3.1.0
- Disclosed:
- Jun 30, 2026
CVE-2026-13693 on NVD →
Bit Form <= 3.0.0 - Missing Authorization
medium
The Bit Form plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.0.0. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 3.0.0
- Fixed in:
- 3.1.0
- Disclosed:
- Jun 30, 2026
CVE-2026-13694 on NVD →
Bit Form – Custom Contact Form, Multi Step, Conversational Form & Payment Form builder [bit-form] <= 2.21.10 (unfixed)
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in bitpressadmin Bit Form bit-form allows SQL Injection.This issue affects Bit Form: from n/a through <= 2.21.10.
- Affected:
- up to 2.21.10
- Fix:
- No patched version reported
- Disclosed:
- Feb 19, 2026
CVE-2026-25418 on NVD →
Bit Form <= 2.21.10 - Authenticated (Administrator+) SQL Injection
medium
The Bit Form plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.21.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and abo...
- CVSS:
- 4.9
- Affected:
- up to 2.21.10
- Fixed in:
- 2.21.11
- Disclosed:
- Jan 28, 2026
CVE-2026-25418 on NVD →
Bit Form – Custom Contact Form, Multi Step, Conversational Form & Payment Form builder [bit-form] < 2.21.7 (closed)
unknown
[en] The Bit Form – Contact Form Plugin plugin for WordPress is vulnerable to unauthorized workflow execution due to missing authorization in the triggerWorkFlow function in all versions up to, and including, 2.21.6. This is due to a logic flaw in the nonce verification where the security check only blocks requests whe...
- Affected:
- up to 2.21.7
- Fixed in:
- 2.21.7
- Disclosed:
- Jan 7, 2026
CVE-2025-14901 on NVD →
Bit Form – Contact Form Plugin <= 2.21.6 - Missing Authorization to Unauthenticated Workflow Replay
medium
The Bit Form – Contact Form Plugin plugin for WordPress is vulnerable to unauthorized workflow execution due to missing authorization in the triggerWorkFlow function in all versions up to, and including, 2.21.6. This is due to a logic flaw in the nonce verification where the security check only blocks requests when bot...
- CVSS:
- 6.5
- Affected:
- up to 2.21.6
- Fixed in:
- 2.21.7
- Disclosed:
- Jan 6, 2026
CVE-2025-14901 on NVD →
Contact Form by Bit Form - Bit Form <= 2.20.3 - Unauthenticated Arbitrary File Upload
critical
The Bit Form builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 2.20.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible....
- CVSS:
- 9.8
- Affected:
- up to 2.20.3
- Fixed in:
- 2.20.4
- Disclosed:
- Aug 14, 2025
CVE-2025-6679 on NVD →
Bit Form – Custom Contact Form, Multi Step, Conversational Form & Payment Form builder [bit-form] < 2.17.6 (closed)
unknown
[en] The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.17.4 via file uploads due to insufficient directory listing prevention and lack of...
- Affected:
- up to 2.17.6
- Fixed in:
- 2.17.6
- Disclosed:
- Jul 2, 2025
CVE-2024-13451 on NVD →
Contact Form by Bit Form <= 2.17.5 - Unauthenticated Sensitive Information Exposure
medium
The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.17.4 via file uploads due to insufficient directory listing prevention and lack of rand...
- CVSS:
- 5.3
- Affected:
- up to 2.17.5
- Fixed in:
- 2.17.6
- Disclosed:
- Jul 1, 2025
CVE-2024-13451 on NVD →
Contact Form by Bit Form <= 2.18.3 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload
medium
The Contact Form by Bit Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.18.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject a...
- CVSS:
- 4.9
- Affected:
- up to 2.18.3
- Fixed in:
- 2.18.4
- Disclosed:
- Apr 24, 2025
CVE-2025-2580 on NVD →
Bit Form – Contact Form Plugin <= 2.18.0 - Open Redirect
high
The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 2.18.0. This is due to insufficient validation on a redirect url. This makes it possible for unauthenticat...
- CVSS:
- 7.2
- Affected:
- up to 2.18.0
- Fixed in:
- 2.18.1
- Disclosed:
- Mar 27, 2025
CVE-2025-30885 on NVD →
Bit Form – Custom Contact Form, Multi Step, Conversational Form & Payment Form builder [bit-form] < 2.18.1 (closed)
unknown
[en] URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Bit Apps Bit Form – Contact Form Plugin allows Phishing. This issue affects Bit Form – Contact Form Plugin: from n/a through 2.18.0.
- Affected:
- up to 2.18.1
- Fixed in:
- 2.18.1
- Disclosed:
- Mar 27, 2025
CVE-2025-30885 on NVD →
Bit Form – Custom Contact Form, Multi Step, Conversational Form & Payment Form builder [bit-form] < 2.17.5 (closed)
unknown
[en] The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.17.4 via the Webhooks integration. This makes it possible for authenticated attackers...
- Affected:
- up to 2.17.5
- Fixed in:
- 2.17.5
- Disclosed:
- Jan 25, 2025
CVE-2024-13450 on NVD →
Contact Form by Bit Form <= 2.17.4 - Authenticated (Administrator+) Server-Side Request Forgery
low
The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.17.4 via the Webhooks integration. This makes it possible for authenticated attackers, wit...
- CVSS:
- 3.8
- Affected:
- up to 2.17.4
- Fixed in:
- 2.17.5
- Disclosed:
- Jan 24, 2025
CVE-2024-13450 on NVD →
Bit Form – Custom Contact Form, Multi Step, Conversational Form & Payment Form builder [bit-form] < 2.17.4 (closed)
unknown
[en] The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the bitform-form-entry-edit endpoint in all versions up to, and including, 2.17.3. This...
- Affected:
- up to 2.17.4
- Fixed in:
- 2.17.4
- Disclosed:
- Dec 25, 2024
CVE-2024-12190 on NVD →
Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder <= 2.17.3 - Missing Authorization to Authenticated (Subscriber+) Form Submission Disclosure
medium
The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the bitform-form-entry-edit endpoint in all versions up to, and including, 2.17.3. This make...
- CVSS:
- 4.3
- Affected:
- up to 2.17.3
- Fixed in:
- 2.17.4
- Disclosed:
- Dec 24, 2024
CVE-2024-12190 on NVD →
Bit Form – Custom Contact Form, Multi Step, Conversational Form & Payment Form builder [bit-form] < 2.15.3 (closed)
unknown
[en] The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 2.15.2 due to improper input validation within the iconUpload function. This makes it possible...
- Affected:
- up to 2.15.3
- Fixed in:
- 2.15.3
- Disclosed:
- Oct 11, 2024
CVE-2024-9507 on NVD →
Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder <= 2.15.2 - Authenticated (Administrator+) Improper Input Validation via iconUpload Function to Arbitrary File Read
medium
The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 2.15.2 due to improper input validation within the iconUpload function. This makes it possible for a...
- CVSS:
- 4.9
- Affected:
- up to 2.15.2
- Fixed in:
- 2.15.3
- Disclosed:
- Oct 10, 2024
CVE-2024-9507 on NVD →
Bit Form – Custom Contact Form, Multi Step, Conversational Form & Payment Form builder [bit-form] < 2.13.12 (closed)
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bit Form Bit Form – Contact Form Plugin allows SQL Injection.This issue affects Bit Form – Contact Form Plugin: from n/a through 2.13.11.
- Affected:
- up to 2.13.12
- Fixed in:
- 2.13.12
- Disclosed:
- Oct 7, 2024
CVE-2024-47335 on NVD →
Bit Form – Custom Contact Form, Multi Step, Conversational Form & Payment Form builder [bit-form] < 2.13.11 (closed)
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Bit Form Bit Form – Contact Form Plugin allows Stored XSS.This issue affects Bit Form – Contact Form Plugin: from n/a through 2.13.10.
- Affected:
- up to 2.13.11
- Fixed in:
- 2.13.11
- Disclosed:
- Oct 6, 2024
CVE-2024-47301 on NVD →
Bit Form – Custom Contact Form, Multi Step, Conversational Form & Payment Form builder [bit-form] < 2.13.11 (closed)
unknown
[en] Unrestricted Upload of File with Dangerous Type vulnerability in Bit Apps Bit Form – Contact Form Plugin allows Code Injection.This issue affects Bit Form – Contact Form Plugin: from n/a through 2.13.10.
- Affected:
- up to 2.13.11
- Fixed in:
- 2.13.11
- Disclosed:
- Oct 5, 2024
CVE-2024-47319 on NVD →
Bit Form – Contact Form Plugin <= 2.13.11 - Authenticated (Administrator+) SQL Injection
medium
The Bit Form – Contact Form Plugin plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.13.11 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrat...
- CVSS:
- 4.9
- Affected:
- up to 2.13.11
- Fixed in:
- 2.13.12
- Disclosed:
- Sep 26, 2024
CVE-2024-47335 on NVD →
Bit Form – Contact Form Plugin <= 2.13.10 - Authenticated (Administrator+) Arbitrary File Upload
high
The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 2.13.10. This makes it possible for authenticated attackers,...
- CVSS:
- 7.2
- Affected:
- up to 2.13.10
- Fixed in:
- 2.13.11
- Disclosed:
- Sep 25, 2024
CVE-2024-47319 on NVD →
Bit Form – Contact Form Plugin <= 2.13.10 - Unauthenticated Stored Cross-Site Scripting
high
The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.13.10 due to insufficient input sanitization and output escaping. This makes it possible f...
- CVSS:
- 7.2
- Affected:
- up to 2.13.10
- Fixed in:
- 2.13.11
- Disclosed:
- Sep 24, 2024
CVE-2024-47301 on NVD →
Bit Form – Custom Contact Form, Multi Step, Conversational Form & Payment Form builder [bit-form] < 2.13.10 (closed)
unknown
[en] The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to arbitrary file read and deletion due to insufficient file path validation in multiple functions in versions 2.0 to 2.13.9. This makes it possible for aut...
- Affected:
- up to 2.13.10
- Fixed in:
- 2.13.10
- Disclosed:
- Aug 20, 2024
CVE-2024-7777 on NVD →
Bit Form – Custom Contact Form, Multi Step, Conversational Form & Payment Form builder [bit-form] < 2.13.5 (closed)
unknown
[en] The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the iconRemove function in versions 2.0 to 2.13.4. This makes it possible for authent...
- Affected:
- up to 2.13.5
- Fixed in:
- 2.13.5
- Disclosed:
- Aug 20, 2024
CVE-2024-7782 on NVD →
Bit Form – Custom Contact Form, Multi Step, Conversational Form & Payment Form builder [bit-form] < 2.13.10 (closed)
unknown
[en] The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to generic SQL Injection via the entryID parameter in versions 2.0 to 2.13.9 due to insufficient escaping on the user-supplied parameter and lack of suffici...
- Affected:
- up to 2.13.10
- Fixed in:
- 2.13.10
- Disclosed:
- Aug 20, 2024
CVE-2024-7702 on NVD →
Bit Form – Custom Contact Form, Multi Step, Conversational Form & Payment Form builder [bit-form] < 2.13.10 (closed)
unknown
[en] The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to arbitrary JavaScript file uploads due to missing input validation in the addCustomCode function in versions 2.0 to 2.13.9. This makes it possible for aut...
- Affected:
- up to 2.13.10
- Fixed in:
- 2.13.10
- Disclosed:
- Aug 20, 2024
CVE-2024-7775 on NVD →
Bit Form – Custom Contact Form, Multi Step, Conversational Form & Payment Form builder [bit-form] < 2.13.10 (closed)
unknown
[en] The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to generic SQL Injection via the id parameter in versions 2.0 to 2.13.9 due to insufficient escaping on the user-supplied parameter and lack of sufficient p...
- Affected:
- up to 2.13.10
- Fixed in:
- 2.13.10
- Disclosed:
- Aug 20, 2024
CVE-2024-7780 on NVD →
Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder 2.0 - 2.13.9 - Authenticated (Administrator+) SQL Injection via getLogHistory Function
high
The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to generic SQL Injection via the entryID parameter in versions 2.0 to 2.13.9 due to insufficient escaping on the user-supplied parameter and lack of sufficient p...
- CVSS:
- 7.2
- Affected:
- 2.0 – 2.13.9
- Fixed in:
- 2.13.10
- Disclosed:
- Aug 19, 2024
CVE-2024-7702 on NVD →
Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder 2.0 - 2.13.9 - Authenticated (Administrator+) Arbitrary JavaScript File Uploads
medium
The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to arbitrary JavaScript file uploads due to missing input validation in the addCustomCode function in versions 2.0 to 2.13.9. This makes it possible for authenti...
- CVSS:
- 5.5
- Affected:
- 2.0 – 2.13.9
- Fixed in:
- 2.13.10
- Disclosed:
- Aug 19, 2024
CVE-2024-7775 on NVD →
Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder 2.0 - 2.13.9 - Authenticated (Administrator+) Arbitrary File Read And Deletion
critical
The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to arbitrary file read and deletion due to insufficient file path validation in multiple functions in versions 2.0 to 2.13.9. This makes it possible for authenti...
- CVSS:
- 9
- Affected:
- 2.0 – 2.13.9
- Fixed in:
- 2.13.10
- Disclosed:
- Aug 19, 2024
CVE-2024-7777 on NVD →
Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder 2.0 - 2.13.9 - Authenticated (Administrator+) SQL Injection
high
The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to generic SQL Injection via the id parameter in versions 2.0 to 2.13.9 due to insufficient escaping on the user-supplied parameter and lack of sufficient prepar...
- CVSS:
- 7.2
- Affected:
- 2.0 – 2.13.9
- Fixed in:
- 2.13.10
- Disclosed:
- Aug 19, 2024
CVE-2024-7780 on NVD →
Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder 2.0 - 2.13.4 - Authenticater (Administrator+) Arbitrary File Deletion
high
The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the iconRemove function in versions 2.0 to 2.13.4. This makes it possible for authenticate...
- CVSS:
- 8.7
- Affected:
- 2.0 – 2.13.4
- Fixed in:
- 2.13.5
- Disclosed:
- Aug 19, 2024
CVE-2024-7782 on NVD →
Bit Form – Custom Contact Form, Multi Step, Conversational Form & Payment Form builder [bit-form] < 2.13.4 (closed)
unknown
[en] The Bit Form plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'iconUpload' function in all versions up to, and including, 2.13.3. This makes it possible for authenticated attackers, with administrator-level and above permissions, to upload arbitrary files on t...
- Affected:
- up to 2.13.4
- Fixed in:
- 2.13.4
- Disclosed:
- Jul 9, 2024
CVE-2024-6123 on NVD →
Bit Form <= 2.13.3 - Authenticated (Administrator+) Arbitrary File Upload
high
The Bit Form plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'iconUpload' function in all versions up to, and including, 2.13.3. This makes it possible for authenticated attackers, with administrator-level and above permissions, to upload arbitrary files on the af...
- CVSS:
- 7.2
- Affected:
- up to 2.13.3
- Fixed in:
- 2.13.4
- Disclosed:
- Jul 8, 2024
CVE-2024-6123 on NVD →
Contact Form Builder Plugin: Multi Step Contact Form, Payment Form, Custom Contact Form Plugin by Bit Form <= 2.10.1 - Unauthenticated Insecure Direct Object Reference to Form Submission Alteration
medium
The Contact Form Builder Plugin: Multi Step Contact Form, Payment Form, Custom Contact Form Plugin by Bit Form plugin for WordPress is vulnerable to unauthorized modification of data due to a insufficient user validation on the bitforms_update_form_entry AJAX action in all versions up to, and including, 2.10.1. This ma...
- CVSS:
- 5.3
- Affected:
- up to 2.10.1
- Fixed in:
- 2.10.2
- Disclosed:
- Mar 13, 2024
CVE-2024-1640 on NVD →
Bit Form – Custom Contact Form, Multi Step, Conversational Form & Payment Form builder [bit-form] < 2.10.2 (closed)
unknown
[en] The Contact Form Builder Plugin: Multi Step Contact Form, Payment Form, Custom Contact Form Plugin by Bit Form plugin for WordPress is vulnerable to unauthorized modification of data due to a insufficient user validation on the bitforms_update_form_entry AJAX action in all versions up to, and including, 2.10.1. Th...
- Affected:
- up to 2.10.2
- Fixed in:
- 2.10.2
- Disclosed:
- Mar 13, 2024
CVE-2024-1640 on NVD →
Bit Form – Custom Contact Form, Multi Step, Conversational Form & Payment Form builder [bit-form] < 2.2.0 (closed)
unknown
[en] The Contact Form Builder by Bit Form WordPress plugin before 2.2.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
- Affected:
- up to 2.2.0
- Fixed in:
- 2.2.0
- Disclosed:
- Aug 14, 2023
CVE-2023-3645 on NVD →
Contact Form Builder by Bit Form <= 2.1.0 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Contact Form Builder by Bit Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 2.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and abov...
- CVSS:
- 4.4
- Affected:
- up to 2.1.0
- Fixed in:
- 2.2.0
- Disclosed:
- Jul 24, 2023
CVE-2023-3645 on NVD →
Bit Form – Custom Contact Form, Multi Step, Conversational Form & Payment Form builder [bit-form] < 1.9 (closed)
unknown
[en] The Bit Form WordPress plugin before 1.9 does not validate the file types uploaded via it's file upload form field, allowing unauthenticated users to upload arbitrary files types such as PHP or HTML files to the server, leading to Remote Code Execution.
- Affected:
- up to 1.9
- Fixed in:
- 1.9
- Disclosed:
- May 15, 2023
CVE-2022-4774 on NVD →
Bit Form <= 1.8.1 - Unauthenticated Arbitrary File Upload to Remote Code Execution
critical
The Bit Form plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the saveFormEntry function in versions up to, and including, 1.8.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code exe...
- CVSS:
- 9.8
- Affected:
- up to 1.8.1
- Fixed in:
- 1.9
- Disclosed:
- Apr 19, 2023
CVE-2022-4774 on NVD →
Bit Form – Custom Contact Form, Multi Step, Conversational Form & Payment Form builder [bit-form] < 2.18.4 (closed)
unknown
- Affected:
- up to 2.18.4
- Fixed in:
- 2.18.4
CVE-2025-2580 on NVD →
Bit Form – Custom Contact Form, Multi Step, Conversational Form & Payment Form builder [bit-form] < 2.20.4 (closed)
unknown
- Affected:
- up to 2.20.4
- Fixed in:
- 2.20.4
CVE-2025-6679 on NVD →