Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Davud Sahibzada

#21935of 56,337
12.4Total CVSS
Vulnerabilities · 2
Medium
2
PT-2026-61834
5.9
2026-07-21
WordPress · Bit Form · CVE-2026-13693
**Name of the Vulnerable Software and Affected Versions** Bit Form versions prior to 3.1.0 **Description** An issue exists where the plugin fails to restrict a form file-field value to a safe path before reading the file and attaching it to a notification email. This allows unauthenticated attackers to perform a path traversal attack to read arbitrary server files, such as the WordPress configuration file. **Recommendations** Update Bit Form to version 3.1.0 or later.
PT-2026-61835
6.5
2026-07-21
WordPress · Bit Form · CVE-2026-13694
**Name of the Vulnerable Software and Affected Versions** Bit Form versions prior to 3.1.0 **Description** An authentication bypass exists due to improper validation of the workflow-trigger token after the associated transient has expired. This allows unauthenticated attackers to re-trigger configured workflow actions for a form, including integrations and notification emails. **Recommendations** Update Bit Form to version 3.1.0 or later.