CVE-2026-13694: Unknown Bit Form
Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.
The Bit Form WordPress plugin before 3.1.0 does not properly validate its workflow-trigger token once the associated transient has expired, allowing unauthenticated attackers to re-trigger a form's configured workflow actions such as notification emails and integrations.
Affected products
- Unknown Bit Form: before 3.1.0 (fixed in 3.1.0)
Published 2026-07-21. Last modified 2026-07-21.