Security Advisory

CVE-2026-16573

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-05 06:00:09
Last updated 2026-08-05 14:11:30
Assigner WPScan
CVSS score not scored
State PUBLISHED

Description

The Bit Form WordPress plugin before 3.2.0 does not sanitize an uploaded signature image before storing it, allowing unauthenticated attackers to upload a crafted SVG file containing JavaScript that executes when the file is viewed, leading to Stored Cross-Site Scripting.