Arbitrary File Upload Vulnerability in Bit Form Builder Plugin by WordPress
CVE-2025-6679
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 15 August 2025
What is CVE-2025-6679?
The Bit Form builder plugin for WordPress is susceptible to an arbitrary file upload vulnerability due to inadequate file type validation across all versions up to and including 2.20.4. This flaw allows unauthenticated attackers to upload harmful files on the server hosting the affected site, potentially leading to remote code execution. The exploit is contingent upon the installation and activation of the PRO version, as well as having a published form that includes an advanced file upload element.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Bit Form β Custom Contact Form, Multi Step, Conversational, Payment & Quiz Form builder * <= 2.20.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved