CVE-2025-15669
Bit Form < 3.1.4 - Admin+ Stored XSS via Conversational Form Progress Label
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Bit Form WordPress plugin before 3.1.4 does not sanitise one of its conversational-form display settings before rendering it on the public-facing form, allowing high-privilege users (such as administrators, who do not hold the unfiltered_html capability on multisite) to store JavaScript that executes in the browser of any visitor who views the form.
| Vendor | unknown |
| Product | bit form |
| Published | Aug 1, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown bit form
Be the first to know when new unknown vulnerabilities affecting unknown bit form are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Bit Form
0 < 3.1.4
References
Credits
Dmitrii Ignatyev WPScan