Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Davud Sahibzada

#21123of 54,922
12.4Total CVSS
Vulnerabilities · 2
Medium
2
PT-2026-61834
5.9
2026-07-21
Undefined · Undefined · CVE-2026-13693
The Bit Form WordPress plugin before 3.1.0 does not restrict a form file-field value to a safe path before reading the file and attaching it to a notification email, allowing unauthenticated attackers to read arbitrary server files such as the WordPress configuration file.
PT-2026-61835
6.5
2026-07-21
Undefined · Undefined · CVE-2026-13694
The Bit Form WordPress plugin before 3.1.0 does not properly validate its workflow-trigger token once the associated transient has expired, allowing unauthenticated attackers to re-trigger a form's configured workflow actions such as notification emails and integrations.