SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-13694

MEDIUM · CVSS 6.5 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-07-21 · Last synced 2026-08-20

CyberRota Analysis

AI-Generated

The Bit Form WordPress plugin prior to version 3.1.0 is vulnerable due to improper validation of workflow-trigger tokens after their associated transients expire, enabling unauthenticated attackers to exploit this flaw. This could lead to unauthorized re-triggering of configured workflow actions, including notification emails and integrations. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential exploitation risks.

CVE
CVE-2026-13694
Severity
MEDIUM
CVSS
6.5
EPSS
0.20%
WordPress

Original NVD Description

The Bit Form WordPress plugin before 3.1.0 does not properly validate its workflow-trigger token once the associated transient has expired, allowing unauthenticated attackers to re-trigger a form's configured workflow actions such as notification emails and integrations.