CVE-2026-13694: Unknown Bit Form

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

The Bit Form WordPress plugin before 3.1.0 does not properly validate its workflow-trigger token once the associated transient has expired, allowing unauthenticated attackers to re-trigger a form's configured workflow actions such as notification emails and integrations.

Affected products

  • Unknown Bit Form: before 3.1.0 (fixed in 3.1.0)

Published 2026-07-21. Last modified 2026-07-21.