CVE-2025-15669

The Bit Form WordPress plugin before 3.1.4 does not sanitise one of its conversational-form display settings before rendering it on the public-facing form, allowing high-privilege users (such as administrators, who do not hold the unfiltered_html capability on multisite) to store JavaScript that executes in the browser of any visitor who views the form.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-01 07:16

Updated : 2026-08-26 16:31


NVD link : CVE-2025-15669

Mitre link : CVE-2025-15669

CVE.ORG link : CVE-2025-15669


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')