CVE-2025-15669
Received Received - Intake

Stored XSS in Bit Form WordPress Plugin

Vulnerability report for CVE-2025-15669, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-01

Last updated on: 2026-08-01

Assigner: WPScan

Description

The Bit Form WordPress plugin before 3.1.4 does not sanitise one of its conversational-form display settings before rendering it on the public-facing form, allowing high-privilege users (such as administrators, who do not hold the unfiltered_html capability on multisite) to store JavaScript that executes in the browser of any visitor who views the form.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-01
Last Modified
2026-08-01
Generated
2026-08-01
AI Q&A
2026-08-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
bit_form wordpress_plugin to 3.1.4 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the Bit Form WordPress plugin before version 3.1.4. It allows high-privilege users like administrators to inject JavaScript code into a form setting that is not properly sanitized. When visitors view the form, the injected script executes in their browsers.

Detection Guidance

Check if the Bit Form WordPress plugin version is below 3.1.4. Inspect the plugin's settings for unsanitized conversational-form display settings that may contain JavaScript. Review form output for injected scripts in the browser console.

Impact Analysis

If you are a visitor viewing a form on a WordPress site using an affected Bit Form plugin version, malicious JavaScript could run in your browser. This may lead to stolen session cookies, redirected pages, or other malicious actions without your knowledge.

Compliance Impact

This vulnerability could potentially affect compliance with GDPR and HIPAA by allowing unauthorized JavaScript execution on forms. High-privilege users could inject malicious scripts that may capture or manipulate user data, violating data protection requirements under these regulations.

Mitigation Strategies

Update the Bit Form plugin to version 3.1.4 or later. Remove any suspicious JavaScript from the conversational-form display settings. Restrict high-privilege user access to prevent unauthorized script injection.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-15669. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart