CyberRota Analysis
AI-GeneratedThe Bit Form WordPress plugin prior to version 3.2.0 is vulnerable due to inadequate sanitization of uploaded signature images, enabling unauthenticated attackers to upload malicious SVG files that execute JavaScript upon viewing. This flaw can lead to Stored Cross-Site Scripting (XSS), potentially compromising user data and site integrity. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk.
Original NVD Description
The Bit Form WordPress plugin before 3.2.0 does not sanitize an uploaded signature image before storing it, allowing unauthenticated attackers to upload a crafted SVG file containing JavaScript that executes when the file is viewed, leading to Stored Cross-Site Scripting.