WordPress Plugin Vulnerabilities

Bit Form < 3.2.0 - Unauthenticated Stored XSS via SVG Signature Upload

Description

The plugin does not sanitize an uploaded signature image before storing it, allowing unauthenticated attackers to upload a crafted SVG file containing JavaScript that executes when the file is viewed, leading to Stored Cross-Site Scripting.

Proof of Concept

Affects Plugins

Fixed in 3.2.0

References

Classification

Type
XSS
CWE
CVSS

Miscellaneous

Original Researcher
Abdullah Kareem (cyberkareem)
Submitter
Abdullah Kareem
Submitter website
Verified
Yes

Timeline

Publicly Published
2026-07-27 (about 1 month ago)
Added
2026-07-27 (about 1 month ago)
Last Updated
2026-08-26 (about 23 hours ago)

Other