Search
Search Results (2 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2025-15669 | 2 Bit Form, Wordpress | 2 Bit Form, Wordpress | 2026-08-01 | N/A |
| The Bit Form WordPress plugin before 3.1.4 does not sanitise one of its conversational-form display settings before rendering it on the public-facing form, allowing high-privilege users (such as administrators, who do not hold the unfiltered_html capability on multisite) to store JavaScript that executes in the browser of any visitor who views the form. | ||||
| CVE-2026-15054 | 2 Bit Form, Wordpress | 2 Bit Form, Wordpress | 2026-07-30 | 3.7 Low |
| The Bit Form WordPress plugin before 3.1.2 does not enforce a form's active/published status on its public form-submission handlers, allowing unauthenticated users to submit entries to, and fire the configured workflows (such as email notifications) of forms the site owner has deactivated or unpublished. | ||||
Page 1 of 1.