plugin

Bit Form Vulnerabilities

49 known security issues reported for the Bit Form WordPress plugin. Most recent disclosed Aug 13, 2026.

3 critical 10 high 14 medium 1 low

Running Bit Form on your site? Check whether your installed version is affected.

Scan your site free

Bit Form <= 3.2.0 - Authenticated (Administrator+) SQL Injection via 'filterText' Parameter

medium

The Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder plugin for WordPress is vulnerable to generic SQL Injection via the 'data[queryCondition]' parameter in all versions up to, and including, 3.2.0 due to insufficient escaping on the user supplied parameter and lack of sufficie...

CVSS:
6.5
Affected:
up to 3.2.0
Fixed in:
3.2.1
Disclosed:
Aug 13, 2026

CVE-2026-16810 on NVD →

Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder < 3.1.4 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 3.1.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-leve...

CVSS:
4.4
Affected:
up to 3.1.4
Fixed in:
3.1.4
Disclosed:
Aug 1, 2026

CVE-2025-15669 on NVD →

Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder < 3.1.2 - Missing Authorization to Unauthenticated Unauthorized Form Submission

medium

The Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to 3.1.2 (exclusive). This makes it possible for unauthenticated attackers to submit forms that they...

CVSS:
5.3
Affected:
up to 3.1.2
Fixed in:
3.1.2
Disclosed:
Jul 30, 2026

CVE-2026-15054 on NVD →

Bit Form <= 3.1.0 - Unauthenticated Stored Cross-Site Scripting

high

The Bit Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an i...

CVSS:
7.2
Affected:
up to 3.1.0
Fixed in:
3.2.0
Disclosed:
Jul 27, 2026

CVE-2026-16573 on NVD →

Bit Form <= 3.1.1 - Authenticated (Subscriber+) Arbitrary File Deletion via '_old' Parameter

high

The Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the deleteFiles function in all versions up to, and including, 3.1.1 This makes it possible for authenticated attackers...

CVSS:
7.1
Affected:
up to 3.1.1
Fixed in:
3.1.2
Disclosed:
Jul 8, 2026

CVE-2026-14372 on NVD →

Bit Form <= 3.0.0 - Unauthenticated Arbitrary File Read

high

The Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.0.0. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can cont...

CVSS:
7.5
Affected:
up to 3.0.0
Fixed in:
3.1.0
Disclosed:
Jun 30, 2026

CVE-2026-13693 on NVD →

Bit Form <= 3.0.0 - Missing Authorization

medium

The Bit Form plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.0.0. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 3.0.0
Fixed in:
3.1.0
Disclosed:
Jun 30, 2026

CVE-2026-13694 on NVD →

Bit Form &#8211; Custom Contact Form, Multi Step, Conversational Form &amp; Payment Form builder [bit-form] <= 2.21.10 (unfixed)

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in bitpressadmin Bit Form bit-form allows SQL Injection.This issue affects Bit Form: from n/a through <= 2.21.10.

Affected:
up to 2.21.10
Fix:
No patched version reported
Disclosed:
Feb 19, 2026

CVE-2026-25418 on NVD →

Bit Form <= 2.21.10 - Authenticated (Administrator+) SQL Injection

medium

The Bit Form plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.21.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and abo...

CVSS:
4.9
Affected:
up to 2.21.10
Fixed in:
2.21.11
Disclosed:
Jan 28, 2026

CVE-2026-25418 on NVD →

Bit Form &#8211; Custom Contact Form, Multi Step, Conversational Form &amp; Payment Form builder [bit-form] < 2.21.7 (closed)

unknown

[en] The Bit Form – Contact Form Plugin plugin for WordPress is vulnerable to unauthorized workflow execution due to missing authorization in the triggerWorkFlow function in all versions up to, and including, 2.21.6. This is due to a logic flaw in the nonce verification where the security check only blocks requests whe...

Affected:
up to 2.21.7
Fixed in:
2.21.7
Disclosed:
Jan 7, 2026

CVE-2025-14901 on NVD →

Bit Form – Contact Form Plugin <= 2.21.6 - Missing Authorization to Unauthenticated Workflow Replay

medium

The Bit Form – Contact Form Plugin plugin for WordPress is vulnerable to unauthorized workflow execution due to missing authorization in the triggerWorkFlow function in all versions up to, and including, 2.21.6. This is due to a logic flaw in the nonce verification where the security check only blocks requests when bot...

CVSS:
6.5
Affected:
up to 2.21.6
Fixed in:
2.21.7
Disclosed:
Jan 6, 2026

CVE-2025-14901 on NVD →

Contact Form by Bit Form - Bit Form <= 2.20.3 - Unauthenticated Arbitrary File Upload

critical

The Bit Form builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 2.20.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible....

CVSS:
9.8
Affected:
up to 2.20.3
Fixed in:
2.20.4
Disclosed:
Aug 14, 2025

CVE-2025-6679 on NVD →

Bit Form &#8211; Custom Contact Form, Multi Step, Conversational Form &amp; Payment Form builder [bit-form] < 2.17.6 (closed)

unknown

[en] The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.17.4 via file uploads due to insufficient directory listing prevention and lack of...

Affected:
up to 2.17.6
Fixed in:
2.17.6
Disclosed:
Jul 2, 2025

CVE-2024-13451 on NVD →

Contact Form by Bit Form <= 2.17.5 - Unauthenticated Sensitive Information Exposure

medium

The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.17.4 via file uploads due to insufficient directory listing prevention and lack of rand...

CVSS:
5.3
Affected:
up to 2.17.5
Fixed in:
2.17.6
Disclosed:
Jul 1, 2025

CVE-2024-13451 on NVD →

Contact Form by Bit Form <= 2.18.3 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload

medium

The Contact Form by Bit Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.18.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject a...

CVSS:
4.9
Affected:
up to 2.18.3
Fixed in:
2.18.4
Disclosed:
Apr 24, 2025

CVE-2025-2580 on NVD →

Bit Form – Contact Form Plugin <= 2.18.0 - Open Redirect

high

The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 2.18.0. This is due to insufficient validation on a redirect url. This makes it possible for unauthenticat...

CVSS:
7.2
Affected:
up to 2.18.0
Fixed in:
2.18.1
Disclosed:
Mar 27, 2025

CVE-2025-30885 on NVD →

Bit Form &#8211; Custom Contact Form, Multi Step, Conversational Form &amp; Payment Form builder [bit-form] < 2.18.1 (closed)

unknown

[en] URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Bit Apps Bit Form – Contact Form Plugin allows Phishing. This issue affects Bit Form – Contact Form Plugin: from n/a through 2.18.0.

Affected:
up to 2.18.1
Fixed in:
2.18.1
Disclosed:
Mar 27, 2025

CVE-2025-30885 on NVD →

Bit Form &#8211; Custom Contact Form, Multi Step, Conversational Form &amp; Payment Form builder [bit-form] < 2.17.5 (closed)

unknown

[en] The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.17.4 via the Webhooks integration. This makes it possible for authenticated attackers...

Affected:
up to 2.17.5
Fixed in:
2.17.5
Disclosed:
Jan 25, 2025

CVE-2024-13450 on NVD →

Contact Form by Bit Form <= 2.17.4 - Authenticated (Administrator+) Server-Side Request Forgery

low

The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.17.4 via the Webhooks integration. This makes it possible for authenticated attackers, wit...

CVSS:
3.8
Affected:
up to 2.17.4
Fixed in:
2.17.5
Disclosed:
Jan 24, 2025

CVE-2024-13450 on NVD →

Bit Form &#8211; Custom Contact Form, Multi Step, Conversational Form &amp; Payment Form builder [bit-form] < 2.17.4 (closed)

unknown

[en] The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the bitform-form-entry-edit endpoint in all versions up to, and including, 2.17.3. This...

Affected:
up to 2.17.4
Fixed in:
2.17.4
Disclosed:
Dec 25, 2024

CVE-2024-12190 on NVD →

Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder <= 2.17.3 - Missing Authorization to Authenticated (Subscriber+) Form Submission Disclosure

medium

The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the bitform-form-entry-edit endpoint in all versions up to, and including, 2.17.3. This make...

CVSS:
4.3
Affected:
up to 2.17.3
Fixed in:
2.17.4
Disclosed:
Dec 24, 2024

CVE-2024-12190 on NVD →

Bit Form &#8211; Custom Contact Form, Multi Step, Conversational Form &amp; Payment Form builder [bit-form] < 2.15.3 (closed)

unknown

[en] The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 2.15.2 due to improper input validation within the iconUpload function. This makes it possible...

Affected:
up to 2.15.3
Fixed in:
2.15.3
Disclosed:
Oct 11, 2024

CVE-2024-9507 on NVD →

Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder <= 2.15.2 - Authenticated (Administrator+) Improper Input Validation via iconUpload Function to Arbitrary File Read

medium

The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 2.15.2 due to improper input validation within the iconUpload function. This makes it possible for a...

CVSS:
4.9
Affected:
up to 2.15.2
Fixed in:
2.15.3
Disclosed:
Oct 10, 2024

CVE-2024-9507 on NVD →

Bit Form &#8211; Custom Contact Form, Multi Step, Conversational Form &amp; Payment Form builder [bit-form] < 2.13.12 (closed)

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bit Form Bit Form – Contact Form Plugin allows SQL Injection.This issue affects Bit Form – Contact Form Plugin: from n/a through 2.13.11.

Affected:
up to 2.13.12
Fixed in:
2.13.12
Disclosed:
Oct 7, 2024

CVE-2024-47335 on NVD →

Bit Form &#8211; Custom Contact Form, Multi Step, Conversational Form &amp; Payment Form builder [bit-form] < 2.13.11 (closed)

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Bit Form Bit Form – Contact Form Plugin allows Stored XSS.This issue affects Bit Form – Contact Form Plugin: from n/a through 2.13.10.

Affected:
up to 2.13.11
Fixed in:
2.13.11
Disclosed:
Oct 6, 2024

CVE-2024-47301 on NVD →

Bit Form &#8211; Custom Contact Form, Multi Step, Conversational Form &amp; Payment Form builder [bit-form] < 2.13.11 (closed)

unknown

[en] Unrestricted Upload of File with Dangerous Type vulnerability in Bit Apps Bit Form – Contact Form Plugin allows Code Injection.This issue affects Bit Form – Contact Form Plugin: from n/a through 2.13.10.

Affected:
up to 2.13.11
Fixed in:
2.13.11
Disclosed:
Oct 5, 2024

CVE-2024-47319 on NVD →

Bit Form – Contact Form Plugin <= 2.13.11 - Authenticated (Administrator+) SQL Injection

medium

The Bit Form – Contact Form Plugin plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.13.11 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrat...

CVSS:
4.9
Affected:
up to 2.13.11
Fixed in:
2.13.12
Disclosed:
Sep 26, 2024

CVE-2024-47335 on NVD →

Bit Form – Contact Form Plugin <= 2.13.10 - Authenticated (Administrator+) Arbitrary File Upload

high

The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 2.13.10. This makes it possible for authenticated attackers,...

CVSS:
7.2
Affected:
up to 2.13.10
Fixed in:
2.13.11
Disclosed:
Sep 25, 2024

CVE-2024-47319 on NVD →

Bit Form – Contact Form Plugin <= 2.13.10 - Unauthenticated Stored Cross-Site Scripting

high

The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.13.10 due to insufficient input sanitization and output escaping. This makes it possible f...

CVSS:
7.2
Affected:
up to 2.13.10
Fixed in:
2.13.11
Disclosed:
Sep 24, 2024

CVE-2024-47301 on NVD →

Bit Form &#8211; Custom Contact Form, Multi Step, Conversational Form &amp; Payment Form builder [bit-form] < 2.13.10 (closed)

unknown

[en] The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to arbitrary file read and deletion due to insufficient file path validation in multiple functions in versions 2.0 to 2.13.9. This makes it possible for aut...

Affected:
up to 2.13.10
Fixed in:
2.13.10
Disclosed:
Aug 20, 2024

CVE-2024-7777 on NVD →

Bit Form &#8211; Custom Contact Form, Multi Step, Conversational Form &amp; Payment Form builder [bit-form] < 2.13.5 (closed)

unknown

[en] The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the iconRemove function in versions 2.0 to 2.13.4. This makes it possible for authent...

Affected:
up to 2.13.5
Fixed in:
2.13.5
Disclosed:
Aug 20, 2024

CVE-2024-7782 on NVD →

Bit Form &#8211; Custom Contact Form, Multi Step, Conversational Form &amp; Payment Form builder [bit-form] < 2.13.10 (closed)

unknown

[en] The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to generic SQL Injection via the entryID parameter in versions 2.0 to 2.13.9 due to insufficient escaping on the user-supplied parameter and lack of suffici...

Affected:
up to 2.13.10
Fixed in:
2.13.10
Disclosed:
Aug 20, 2024

CVE-2024-7702 on NVD →

Bit Form &#8211; Custom Contact Form, Multi Step, Conversational Form &amp; Payment Form builder [bit-form] < 2.13.10 (closed)

unknown

[en] The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to arbitrary JavaScript file uploads due to missing input validation in the addCustomCode function in versions 2.0 to 2.13.9. This makes it possible for aut...

Affected:
up to 2.13.10
Fixed in:
2.13.10
Disclosed:
Aug 20, 2024

CVE-2024-7775 on NVD →

Bit Form &#8211; Custom Contact Form, Multi Step, Conversational Form &amp; Payment Form builder [bit-form] < 2.13.10 (closed)

unknown

[en] The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to generic SQL Injection via the id parameter in versions 2.0 to 2.13.9 due to insufficient escaping on the user-supplied parameter and lack of sufficient p...

Affected:
up to 2.13.10
Fixed in:
2.13.10
Disclosed:
Aug 20, 2024

CVE-2024-7780 on NVD →

Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder 2.0 - 2.13.9 - Authenticated (Administrator+) SQL Injection via getLogHistory Function

high

The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to generic SQL Injection via the entryID parameter in versions 2.0 to 2.13.9 due to insufficient escaping on the user-supplied parameter and lack of sufficient p...

CVSS:
7.2
Affected:
2.0 – 2.13.9
Fixed in:
2.13.10
Disclosed:
Aug 19, 2024

CVE-2024-7702 on NVD →

Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder 2.0 - 2.13.9 - Authenticated (Administrator+) Arbitrary JavaScript File Uploads

medium

The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to arbitrary JavaScript file uploads due to missing input validation in the addCustomCode function in versions 2.0 to 2.13.9. This makes it possible for authenti...

CVSS:
5.5
Affected:
2.0 – 2.13.9
Fixed in:
2.13.10
Disclosed:
Aug 19, 2024

CVE-2024-7775 on NVD →

Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder 2.0 - 2.13.9 - Authenticated (Administrator+) Arbitrary File Read And Deletion

critical

The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to arbitrary file read and deletion due to insufficient file path validation in multiple functions in versions 2.0 to 2.13.9. This makes it possible for authenti...

CVSS:
9
Affected:
2.0 – 2.13.9
Fixed in:
2.13.10
Disclosed:
Aug 19, 2024

CVE-2024-7777 on NVD →

Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder 2.0 - 2.13.9 - Authenticated (Administrator+) SQL Injection

high

The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to generic SQL Injection via the id parameter in versions 2.0 to 2.13.9 due to insufficient escaping on the user-supplied parameter and lack of sufficient prepar...

CVSS:
7.2
Affected:
2.0 – 2.13.9
Fixed in:
2.13.10
Disclosed:
Aug 19, 2024

CVE-2024-7780 on NVD →

Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder 2.0 - 2.13.4 - Authenticater (Administrator+) Arbitrary File Deletion

high

The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the iconRemove function in versions 2.0 to 2.13.4. This makes it possible for authenticate...

CVSS:
8.7
Affected:
2.0 – 2.13.4
Fixed in:
2.13.5
Disclosed:
Aug 19, 2024

CVE-2024-7782 on NVD →

Bit Form &#8211; Custom Contact Form, Multi Step, Conversational Form &amp; Payment Form builder [bit-form] < 2.13.4 (closed)

unknown

[en] The Bit Form plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'iconUpload' function in all versions up to, and including, 2.13.3. This makes it possible for authenticated attackers, with administrator-level and above permissions, to upload arbitrary files on t...

Affected:
up to 2.13.4
Fixed in:
2.13.4
Disclosed:
Jul 9, 2024

CVE-2024-6123 on NVD →

Bit Form <= 2.13.3 - Authenticated (Administrator+) Arbitrary File Upload

high

The Bit Form plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'iconUpload' function in all versions up to, and including, 2.13.3. This makes it possible for authenticated attackers, with administrator-level and above permissions, to upload arbitrary files on the af...

CVSS:
7.2
Affected:
up to 2.13.3
Fixed in:
2.13.4
Disclosed:
Jul 8, 2024

CVE-2024-6123 on NVD →

Contact Form Builder Plugin: Multi Step Contact Form, Payment Form, Custom Contact Form Plugin by Bit Form <= 2.10.1 - Unauthenticated Insecure Direct Object Reference to Form Submission Alteration

medium

The Contact Form Builder Plugin: Multi Step Contact Form, Payment Form, Custom Contact Form Plugin by Bit Form plugin for WordPress is vulnerable to unauthorized modification of data due to a insufficient user validation on the bitforms_update_form_entry AJAX action in all versions up to, and including, 2.10.1. This ma...

CVSS:
5.3
Affected:
up to 2.10.1
Fixed in:
2.10.2
Disclosed:
Mar 13, 2024

CVE-2024-1640 on NVD →

Bit Form &#8211; Custom Contact Form, Multi Step, Conversational Form &amp; Payment Form builder [bit-form] < 2.10.2 (closed)

unknown

[en] The Contact Form Builder Plugin: Multi Step Contact Form, Payment Form, Custom Contact Form Plugin by Bit Form plugin for WordPress is vulnerable to unauthorized modification of data due to a insufficient user validation on the bitforms_update_form_entry AJAX action in all versions up to, and including, 2.10.1. Th...

Affected:
up to 2.10.2
Fixed in:
2.10.2
Disclosed:
Mar 13, 2024

CVE-2024-1640 on NVD →

Bit Form &#8211; Custom Contact Form, Multi Step, Conversational Form &amp; Payment Form builder [bit-form] < 2.2.0 (closed)

unknown

[en] The Contact Form Builder by Bit Form WordPress plugin before 2.2.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

Affected:
up to 2.2.0
Fixed in:
2.2.0
Disclosed:
Aug 14, 2023

CVE-2023-3645 on NVD →

Contact Form Builder by Bit Form <= 2.1.0 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Contact Form Builder by Bit Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 2.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and abov...

CVSS:
4.4
Affected:
up to 2.1.0
Fixed in:
2.2.0
Disclosed:
Jul 24, 2023

CVE-2023-3645 on NVD →

Bit Form &#8211; Custom Contact Form, Multi Step, Conversational Form &amp; Payment Form builder [bit-form] < 1.9 (closed)

unknown

[en] The Bit Form WordPress plugin before 1.9 does not validate the file types uploaded via it's file upload form field, allowing unauthenticated users to upload arbitrary files types such as PHP or HTML files to the server, leading to Remote Code Execution.

Affected:
up to 1.9
Fixed in:
1.9
Disclosed:
May 15, 2023

CVE-2022-4774 on NVD →

Bit Form <= 1.8.1 - Unauthenticated Arbitrary File Upload to Remote Code Execution

critical

The Bit Form plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the saveFormEntry function in versions up to, and including, 1.8.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code exe...

CVSS:
9.8
Affected:
up to 1.8.1
Fixed in:
1.9
Disclosed:
Apr 19, 2023

CVE-2022-4774 on NVD →

Bit Form &#8211; Custom Contact Form, Multi Step, Conversational Form &amp; Payment Form builder [bit-form] < 2.18.4 (closed)

unknown
Affected:
up to 2.18.4
Fixed in:
2.18.4

CVE-2025-2580 on NVD →

Bit Form &#8211; Custom Contact Form, Multi Step, Conversational Form &amp; Payment Form builder [bit-form] < 2.20.4 (closed)

unknown
Affected:
up to 2.20.4
Fixed in:
2.20.4

CVE-2025-6679 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database