← WordPress Vulnerabilities
WordPress security by component

Bit Form

Bit Form is a WordPress component with 21 published CVE records in this archive. The latest tracked vulnerability was published Jul 21, 2026; the highest CVE/CNA score is 9.8.

Plugin slug: bit-form

CVE-2026-13694: Bit Form: A security weakness

Bit Form is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is < 3.1.0.

PublishedJul 21, 2026
Known safe version3.1.0
Safe version
Jul 21, 2026 CVE-2026-13694
Bit Form: A security weakness
Bit Form is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is < 3.1.0.
3.1.0
CVE6.5
NVDPending
Jul 21, 2026 CVE-2026-13693
Bit Form: A security weakness
Bit Form is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is < 3.1.0.
3.1.0
CVE5.9
NVDPending
Jul 09, 2026 CVE-2026-14372
Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder: Code execution
Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder is affected by code execution. Exploitation requires at least subscriber-level access. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is <= 3.1.1.
> 3.1.1
CVE7.1
NVDPending
Feb 19, 2026 CVE-2026-25418
Bit Form: SQL injection
Bit Form is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.6
NVDPending
Jan 07, 2026 CVE-2025-14901
Bit Form – Contact Form Plugin: A security weakness
Bit Form – Contact Form Plugin is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVDPending
Aug 15, 2025 CVE-2025-6679
Bit Form builder: Dangerous file upload
Bit Form builder is affected by dangerous file upload. The vulnerable path is reachable without authentication. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
See mitigation notes
CVE9.8
NVDPending
Jul 02, 2025 CVE-2024-13451
Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder: Sensitive information exposure
Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE5.3
NVD7.5
Apr 25, 2025 CVE-2025-2580
Contact Form by Bit Form: Cross-site scripting
Contact Form by Bit Form is affected by cross-site scripting. Exploitation requires at least author-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.9
NVDPending
Mar 27, 2025 CVE-2025-30885
Bit Form: An open redirect
Bit Form is affected by an open redirect. Exposure depends on how the affected operation is made reachable by the site. A crafted link can redirect visitors from the trusted site to an attacker-controlled destination.
See mitigation notes
CVE4.7
NVDPending
Jan 25, 2025 CVE-2024-13450
Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder: Server-side request forgery
Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder is affected by server-side request forgery. Exploitation requires at least administrator-level access. The vulnerable server can be induced to make attacker-selected network requests.
See mitigation notes
CVE3.8
NVD6.5
Oct 11, 2024 CVE-2024-9507
Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder: Filesystem traversal
Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder is affected by filesystem traversal. Exploitation requires at least administrator-level access. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE4.9
NVDPending
Oct 07, 2024 CVE-2024-47335
Bit Form: SQL injection
Bit Form is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.6
NVDPending
Oct 06, 2024 CVE-2024-47301
Bit Form: Cross-site scripting
Bit Form is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVDPending
Oct 05, 2024 CVE-2024-47319
Bit Form: Dangerous file upload
Bit Form is affected by dangerous file upload. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
See mitigation notes
CVE8.0
NVDPending
Aug 20, 2024 CVE-2024-7782
Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder: Code execution
Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder is affected by code execution. Exploitation requires at least administrator-level access. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE8.7
NVD6.5
Aug 20, 2024 CVE-2024-7780
Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder: SQL injection
Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder is affected by SQL injection. Exploitation requires at least administrator-level access. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.2
NVDPending
Aug 20, 2024 CVE-2024-7777
Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder: Filesystem traversal
Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder is affected by filesystem traversal. Exploitation requires at least administrator-level access. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE9.0
NVD9.0
Aug 20, 2024 CVE-2024-7775
Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder: A security weakness
Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder is affected by a security weakness. Exploitation requires at least administrator-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.5
NVD4.8
Aug 20, 2024 CVE-2024-7702
Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder: SQL injection
Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder is affected by SQL injection. Exploitation requires at least administrator-level access. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.2
NVDPending
Jul 09, 2024 CVE-2024-6123
Bit Form: Dangerous file upload
Bit Form is affected by dangerous file upload. Exploitation requires an authenticated WordPress account. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
See mitigation notes
CVE7.2
NVDPending
May 15, 2023 CVE-2022-4774
Bit Form: Code execution
Bit Form is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE9.8
NVD9.8