Show filters
12 Total Results
Displaying 11-12 of 12
Sort by:
Attacker Value
Unknown
CVE-2024-1640
Disclosure Date: March 13, 2024 (last updated April 01, 2024)
The Contact Form Builder Plugin: Multi Step Contact Form, Payment Form, Custom Contact Form Plugin by Bit Form plugin for WordPress is vulnerable to unauthorized modification of data due to a insufficient user validation on the bitforms_update_form_entry AJAX action in all versions up to, and including, 2.10.1. This makes it possible for unauthenticated attackers to modify form submissions.
0
Attacker Value
Unknown
CVE-2022-4774
Disclosure Date: May 15, 2023 (last updated October 08, 2023)
The Bit Form WordPress plugin before 1.9 does not validate the file types uploaded via it's file upload form field, allowing unauthenticated users to upload arbitrary files types such as PHP or HTML files to the server, leading to Remote Code Execution.
0