PT-2026-66998 · WordPress · Bit Form
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Bit Form WordPress plugin versions prior to 3.1.4
Description
Stored Cross-Site Scripting (XSS) occurs because the plugin fails to sanitize a conversational-form display setting before rendering it on the public-facing form. This allows high-privilege users, such as administrators without the
unfiltered html capability on multisite installations, to inject JavaScript that executes in the browser of any visitor viewing the form.Recommendations
Update Bit Form WordPress plugin to version 3.1.4 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bit Form