The Bit Form builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 2.20.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. For this to be exploitable, the PRO version needs to be installed and activated as well. Additionally a form with an advanced file upload element needs to be published.
Metrics
Affected Vendors & Products
References
History
Sat, 16 Aug 2025 21:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Bitpressadmin
Bitpressadmin contact Form By Bit Form Multi Step Form Wordpress Wordpress wordpress |
|
Vendors & Products |
Bitpressadmin
Bitpressadmin contact Form By Bit Form Multi Step Form Wordpress Wordpress wordpress |
Fri, 15 Aug 2025 12:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 15 Aug 2025 06:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Bit Form builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 2.20.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. For this to be exploitable, the PRO version needs to be installed and activated as well. Additionally a form with an advanced file upload element needs to be published. | |
Title | Contact Form by Bit Form - Bit Form <= 2.20.3 - Unauthenticated Arbitrary File Upload | |
Weaknesses | CWE-434 | |
References |
|
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-08-15T12:05:26.986Z
Reserved: 2025-06-25T19:36:25.214Z
Link: CVE-2025-6679

Updated: 2025-08-15T12:05:18.634Z

Status : Awaiting Analysis
Published: 2025-08-15T07:15:28.600
Modified: 2025-08-15T13:12:51.217
Link: CVE-2025-6679

No data.