SQL Injection Vulnerability in Bit Form Plugin by Bitpressadmin
CVE-2026-25418

7.6HIGH

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
19 February 2026

What is CVE-2026-25418?

The Bit Form plugin by Bitpressadmin is exposed to an SQL Injection vulnerability that allows attackers to manipulate SQL queries. This flaw can be exploited to gain unauthorized access to the database, extract sensitive information, or perform other malicious operations. The issue has been identified in versions of Bit Form up to and including 2.21.10, increasing the risk for users who have not updated their plugin. It is crucial for site administrators to apply patches and ensure their WordPress installations are secure against such vulnerabilities.

Affected Version(s)

Bit Form 0 <= 2.21.10

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Trương Hữu Phúc (truonghuuphuc) | Patchstack Bug Bounty Program
.