Security Advisory

CVE-2026-13694

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-21 06:00:01
Last updated 2026-07-21 15:19:28
Assigner WPScan
CVSS score not scored
State PUBLISHED

Description

The Bit Form WordPress plugin before 3.1.0 does not properly validate its workflow-trigger token once the associated transient has expired, allowing unauthenticated attackers to re-trigger a form's configured workflow actions such as notification emails and integrations.