Back to CVE List

CVE-2026-15054

Vulnerability Description

The Bit Form WordPress plugin before 3.1.2 does not enforce a form's active/published status on its public form-submission handlers, allowing unauthenticated users to submit entries to, and fire the configured workflows (such as email notifications) of forms the site owner has deactivated or unpublished.

Vulnerability Details

Published Date
Last Modified
Source
NVD
Vendor
Unknown
Product
Bit Form

External References

Discussion (0)

Add Comment

No comments yet. Be the first!