SQL Injection Vulnerability in Bit Form Contact Forms Plugin for WordPress
CVE-2026-16810
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 14 August 2026
What is CVE-2026-16810?
The Bit Form β Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder plugin for WordPress is susceptible to SQL Injection attacks due to insufficient escaping of user-supplied input through the 'data[queryCondition]' parameter. This vulnerability affects all versions up to and including 3.2.0, allowing authenticated attackers with administrator-level access to manipulate existing SQL queries. As a result, attackers could potentially extract sensitive data from the database, highlighting the necessity for immediate updates and security measures.
Affected Version(s)
Bit Form β Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder 0 <= 3.2.0