CVE-2024-13451
- EPSS 0.07%
- Veröffentlicht 02.07.2025 05:29:18
- Zuletzt bearbeitet 10.07.2025 15:26:49
The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.17.4 via file upl...
- EPSS 0.48%
- Veröffentlicht 05.10.2024 13:15:14
- Zuletzt bearbeitet 07.10.2024 17:48:28
Unrestricted Upload of File with Dangerous Type vulnerability in Bit Apps Bit Form – Contact Form Plugin allows Code Injection.This issue affects Bit Form – Contact Form Plugin: from n/a through 2.13.10.
CVE-2024-43251
- EPSS 0.51%
- Veröffentlicht 26.08.2024 21:15:25
- Zuletzt bearbeitet 17.09.2024 18:10:36
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Bit Apps Bit Form Pro.This issue affects Bit Form Pro: from n/a through 2.6.4.
CVE-2024-43248
- EPSS 0.25%
- Veröffentlicht 19.08.2024 18:15:11
- Zuletzt bearbeitet 06.09.2024 16:32:16
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bit Apps Bit Form Pro allows File Manipulation.This issue affects Bit Form Pro: from n/a through 2.6.4.
CVE-2024-43249
- EPSS 1.88%
- Veröffentlicht 19.08.2024 18:15:11
- Zuletzt bearbeitet 06.09.2024 16:30:49
Unrestricted Upload of File with Dangerous Type vulnerability in Bit Apps Bit Form Pro allows Command Injection.This issue affects Bit Form Pro: from n/a through 2.6.4.
CVE-2024-43250
- EPSS 0.13%
- Veröffentlicht 19.08.2024 18:15:11
- Zuletzt bearbeitet 06.09.2024 16:02:16
Incorrect Authorization vulnerability in Bit Apps Bit Form Pro bitformpro allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Bit Form Pro: from n/a through 2.6.4.
CVE-2024-6123
- EPSS 8.56%
- Veröffentlicht 09.07.2024 08:15:10
- Zuletzt bearbeitet 21.11.2024 09:49:00
The Bit Form plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'iconUpload' function in all versions up to, and including, 2.13.3. This makes it possible for authenticated attackers, with administ...
CVE-2022-4774
- EPSS 6.86%
- Veröffentlicht 15.05.2023 13:15:09
- Zuletzt bearbeitet 24.01.2025 22:15:32
The Bit Form WordPress plugin before 1.9 does not validate the file types uploaded via it's file upload form field, allowing unauthenticated users to upload arbitrary files types such as PHP or HTML files to the server, leading to Remote Code Executi...