CVE-2026-15054: Unknown Bit Form
Low severity, CVSS 3.7. EPSS: 0.2% chance of exploitation in the next 30 days.
The Bit Form WordPress plugin before 3.1.2 does not enforce a form's active/published status on its public form-submission handlers, allowing unauthenticated users to submit entries to, and fire the configured workflows (such as email notifications) of forms the site owner has deactivated or unpublished.
Affected products
- Unknown Bit Form: before 3.1.2 (fixed in 3.1.2)
Published 2026-07-30. Last modified 2026-07-30.