SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-15054

LOW · CVSS 3.7 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

The Bit Form WordPress plugin prior to version 3.1.2 is vulnerable as it fails to enforce the active or published status of forms, enabling unauthenticated users to submit entries to deactivated or unpublished forms. This could lead to unauthorized submissions triggering workflows, such as email notifications, potentially causing information leakage or spam. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate these risks.

CVE
CVE-2026-15054
Severity
LOW
CVSS
3.7
EPSS
0.20%
WordPress

Original NVD Description

The Bit Form WordPress plugin before 3.1.2 does not enforce a form's active/published status on its public form-submission handlers, allowing unauthenticated users to submit entries to, and fire the configured workflows (such as email notifications) of forms the site owner has deactivated or unpublished.