WordPress · Bit Form · CVE-2026-14372
**Name of the Vulnerable Software and Affected Versions**
Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder versions prior to 3.1.2
**Description**
Insufficient file path validation in the `deleteFiles()` function allows authenticated attackers with subscriber-level access and above to delete arbitrary files on the server. This action can lead to remote code execution if critical files, such as `wp-config`, are deleted.
**Recommendations**
Update the plugin to version 3.1.2 or later.