GHSA-phfq-m343-hfqpLowCVSS 3.7

The Bit Form WordPress plugin before 3.1.2 does not enforce a form's active/published status on...

Published
July 30, 2026
Last Modified
July 30, 2026

🔗 CVE IDs covered (1)

📋 Description

The Bit Form WordPress plugin before 3.1.2 does not enforce a form's active/published status on its public form-submission handlers, allowing unauthenticated users to submit entries to, and fire the configured workflows (such as email notifications) of forms the site owner has deactivated or unpublished.

🔗 References (3)