SQL Injection Vulnerability in Bit Form Plugin by Bitpressadmin
CVE-2026-25418
7.6HIGH
What is CVE-2026-25418?
The Bit Form plugin by Bitpressadmin is exposed to an SQL Injection vulnerability that allows attackers to manipulate SQL queries. This flaw can be exploited to gain unauthorized access to the database, extract sensitive information, or perform other malicious operations. The issue has been identified in versions of Bit Form up to and including 2.21.10, increasing the risk for users who have not updated their plugin. It is crucial for site administrators to apply patches and ensure their WordPress installations are secure against such vulnerabilities.
Affected Version(s)
Bit Form 0 <= 2.21.10
References
CVSS V3.1
Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Trương Hữu Phúc (truonghuuphuc) | Patchstack Bug Bounty Program