CVE-2026-15054
Last modified
CVE-2026-15054 is a low-severity vulnerability rated 3.7/10 on the CVSS scale. The Bit Form WordPress plugin before 3.1.2 does not enforce a form's active/published status on its public form-submission handlers, allowing unauthenticated users to submit entries to, and fire the configured workflows (such as email notifications) of forms the site owner has deactivated or unpublished.. EPSS estimates a 0.15% chance of exploitation in the next 30 days.
Description
The Bit Form WordPress plugin before 3.1.2 does not enforce a form's active/published status on its public form-submission handlers, allowing unauthenticated users to submit entries to, and fire the configured workflows (such as email notifications) of forms the site owner has deactivated or unpublished.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Unknown | Bit Form | < 3.1.2 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-15054?
How severe is CVE-2026-15054?
How do I fix CVE-2026-15054?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-15047The s2Member WordPress plugin before 260805 does not escape…6.8
- CVE-2026-15048The Geeky Bot WordPress plugin before 1.2.8 does not perfor…7.5
- CVE-2026-15049The Depicter — Popup & Slider Builder WordPress plugin befor…7.2
- CVE-2026-1505A vulnerability was found in D-Link DIR-615 4.10. This issue…7.3
- CVE-2026-15052The MailChimp Subscribe Form, Optin Builder, PopUp Builder, …7.2
- CVE-2026-15053Tanium addressed a denial of service vulnerability in Tanium…7.5
- CVE-2026-15055In Bouncy Castle for Java before 1.85, PKCS#8 / PBES2 decryp…8.2
- CVE-2026-15056The StoreEngine — Complete eCommerce Solution with Membershi…6.5
- CVE-2026-15057IBM WebSphere Application Server - Liberty 17.0.0.3 through …7.5
- CVE-2026-15058Improper authorization in the secure messages deletion endpo…3.1
- CVE-2026-15059Local unprivileged users can terminate arbitrary local proce…5.5
- CVE-2026-1506A vulnerability was determined in D-Link DIR-615 4.10. Impac…7.3
Are you affected by CVE-2026-15054?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
