The Bit Form WordPress plugin before 3.1.2 does not enforce a form's active/published status on its public form-submission handlers, allowing unauthenticated users to submit entries to, and fire the configured workflows (such as email notifications) of forms the site owner has deactivated or unpublished.
References
Configurations
No configuration.
History
30 Jul 2026, 19:17
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 3.7 |
| CWE | CWE-862 |
30 Jul 2026, 06:25
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-30 06:25
Updated : 2026-07-30 19:17
NVD link : CVE-2026-15054
Mitre link : CVE-2026-15054
CVE.ORG link : CVE-2026-15054
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization
