Pricing
Case studies
Login
Start trial
Bit Form
Bit Apps
Developer
N/A
Latest version
N/A
Installations
N/A
Last updated
WordPress Plugin
No VDP
Claim ownership
Report vulnerability
Vulnerabilities
Security Contributors
Vulnerability history
0 present
21 patched
4 Mitigation rules
WordPress Bit Form plugin 2.0 - 2.13.9 - Authenticated (Administrator+) SQL Injection vulnerability
2.0-2.13.9
02/02/2026
SQL Injection vulnerability
<= 2.21.10
28/01/2026
WordPress Bit Form - Contact Form Plugin plugin <= 2.21.6 - Missing Authorization to Unauthenticated Workflow Replay vulnerability
<= 2.21.6
07/01/2026
Unauthenticated Arbitrary File Upload vulnerability
<= 2.20.3
15/08/2025
Unauthenticated Sensitive Information Exposure vulnerability
<= 2.17.5
02/07/2025
Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload vulnerability
<= 2.18.3
24/04/2025
Open Redirection vulnerability
<= 2.18.0
27/03/2025
Authenticated (Administrator+) Server-Side Request Forgery vulnerability
<= 2.17.4
27/01/2025
Missing Authorization to Authenticated (Subscriber+) Form Submission Disclosure vulnerability
<= 2.17.3
24/12/2024
Authenticated (Administrator+) Improper Input Validation to Arbitrary File Read vulnerability
<= 2.15.2
10/10/2024
SQL Injection vulnerability
<= 2.13.11
26/09/2024
Arbitrary File Upload vulnerability
<= 2.13.10
25/09/2024
Cross Site Scripting (XSS) vulnerability
<= 2.13.10
24/09/2024
WordPress BitForm plugin 2.0 - 2.13.9 - Authenticated (Administrator+) Arbitrary File Read And Deletion vulnerability
2.0 - 2.13.9
20/08/2024
WordPress BitForm plugin 2.0 - 2.13.9 - Authenticated (Administrator+) Arbitrary JavaScript File Uploads vulnerability
2.0 - 2.13.9
20/08/2024
WordPress BitForm plugin 2.0 - 2.13.9 - Authenticated (Administrator+) SQL Injection via getLogHistory Function vulnerability
2.0 - 2.13.9
20/08/2024
WordPress BitForm plugin 2.0 - 2.13.4 - Authenticater (Administrator+) Arbitrary File Deletion vulnerability
2.0 - 2.13.4
20/08/2024
Authenticated (Administrator+) Arbitrary File Upload vulnerability
<= 2.12.3
09/07/2024
Unauthenticated Insecure Direct Object Reference to Form Submission Alteration vulnerability
<= 2.10.1
13/03/2024
Admin+ Stored XSS vulnerability
< 2.2.0
27/07/2023
RCE via Unauthenticated Arbitrary File Upload vulnerability
< 1.9
15/05/2023