PT-2026-61835 · WordPress · Bit Form
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Bit Form versions prior to 3.1.0
Description
An authentication bypass exists due to improper validation of the workflow-trigger token after the associated transient has expired. This allows unauthenticated attackers to re-trigger configured workflow actions for a form, including integrations and notification emails.
Recommendations
Update Bit Form to version 3.1.0 or later.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bit Form