What the vulnerability does
01Description
The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 2.15.2 due to improper input validation within the iconUpload function. This makes it possible for authenticated attackers, with Administrator-level access and above, to leverage a PHP filter chain attack and read the contents of arbitrary files on the server, which can contain sensitive information.
Explanation of Vulnerability in Simple Terms
02Summary
Bit Form contains an improper input validation flaw that allows high-privilege users to read sensitive data they should not access. The vulnerability affects all versions up to 2.15.2. An authenticated administrator can exploit this to view confidential information stored within the form builder. Update to a version newer than 2.15.2 to resolve this issue.
What an attacker can do
03Attacker Capabilities
Read sensitive data accessible only to higher-privilege users within the form builder.
Potential impact on your site
04Site Impact
Administrators with access to Bit Form could view confidential form data or settings they shouldn't access.
Conditions required to exploit
05Prerequisites
Attacker must have high-level administrative privileges on the WordPress site.
Key dates
06Disclosure timeline
October 11, 2024
CVE published
April 8, 2026
Record updated