Stored Cross-Site Scripting in BitForm Plugin for WordPress
CVE-2026-8891
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 27 May 2026
What is CVE-2026-8891?
The BitForm plugin for WordPress suffers from a Stored Cross-Site Scripting vulnerability due to inadequate input sanitization and output escaping. Specifically, the 'bitform' shortcode allows attackers with contributor-level access and higher to inject malicious scripts into 'width' and 'height' attributes. This occurs within the Shortcode::shortcode() function, where values are directly interpolated into an 's 'style' attribute. Consequently, when users access affected pages, the injected scripts are executed, compromising site security and potentially exposing sensitive user information.
Affected Version(s)
BitForm β Data management solution for WordPress 0 <= 1.1.0