CVE-2026-13694

MEDIUM

Bit Form < 3.1.0 - Unauthenticated Workflow Trigger via Authentication Bypass

Title source: cna
STIX 2.1

Description

The Bit Form WordPress plugin before 3.1.0 does not properly validate its workflow-trigger token once the associated transient has expired, allowing unauthenticated attackers to re-trigger a form's configured workflow actions such as notification emails and integrations.

References (1)

Core 1
Core References
Exploit exploit vdb-entry technical-description
https://wpscan.com/vulnerability/3ed474fc-8363-4068-9a12-3d63be4a81bd/

Scores

CVSS v3 6.5
EPSS 0.0020
EPSS Percentile 10.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (1)
None/Bit Form < 3.1.0
Published Jul 21, 2026
Tracked Since Jul 21, 2026