CyberRota Analysis
AI-GeneratedThe Bit Form WordPress plugin prior to version 3.1.2 is vulnerable as it fails to enforce the active or published status of forms, enabling unauthenticated users to submit entries to deactivated or unpublished forms. This could lead to unauthorized submissions triggering workflows, such as email notifications, potentially causing information leakage or spam. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate these risks.
Original NVD Description
The Bit Form WordPress plugin before 3.1.2 does not enforce a form's active/published status on its public form-submission handlers, allowing unauthenticated users to submit entries to, and fire the configured workflows (such as email notifications) of forms the site owner has deactivated or unpublished.