CVE-2026-15054: Unknown Bit Form

Low severity, CVSS 3.7. EPSS: 0.2% chance of exploitation in the next 30 days.

The Bit Form WordPress plugin before 3.1.2 does not enforce a form's active/published status on its public form-submission handlers, allowing unauthenticated users to submit entries to, and fire the configured workflows (such as email notifications) of forms the site owner has deactivated or unpublished.

Affected products

  • Unknown Bit Form: before 3.1.2 (fixed in 3.1.2)

Published 2026-07-30. Last modified 2026-07-30.