PatchSiren cyber security CVE debrief
CVE-2025-14901 bitpressadmin CVE debrief
The Bit Form – Contact Form Plugin for WordPress is vulnerable to unauthorized workflow execution due to a logic flaw in the nonce verification process. This allows unauthenticated attackers to replay form workflow executions and trigger integrations like webhooks and email notifications if they can obtain the entry ID and log IDs from a legitimate form submission response.
- Vendor
- bitpressadmin
- Product
- Bit Form – Custom Contact Form, Multi Step, Conversational Form & Payment Form builder
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-01-07
- Original CVE updated
- 2026-09-30
- Advisory published
- 2026-01-07
- Advisory updated
- 2026-09-30
Who should care
Defenders responsible for WordPress environments using the Bit Form plugin should assess exposure and prioritize updating the plugin to prevent unauthorized workflow execution. This involves verifying the plugin version, monitoring for suspicious activities, and implementing security measures to restrict access to form workflow executions.
Why it matters
The Bit Form plugin vulnerability allows unauthenticated attackers to potentially trigger integrations and replay workflow executions. Defenders should assess exposure, verify and update the plugin, and implement security measures to prevent unauthorized access.
- Potential unauthorized triggering of integrations like webhooks and email notifications.
- Possible replay of form workflow executions by unauthenticated attackers.
- Need for verification of plugin version and exposure in WordPress environments.
- Requirement for compensating controls to monitor and restrict access to form workflow executions.
Technical summary
The Bit Form – Contact Form Plugin for WordPress is vulnerable to unauthorized workflow execution due to missing authorization in the triggerWorkFlow function. This flaw allows unauthenticated attackers to replay form workflow executions and trigger all configured integrations, including webhooks and email notifications, if they can obtain the entry ID and log IDs from a legitimate form submission response.
Defensive priority
Defenders should prioritize verifying and updating the Bit Form plugin to prevent unauthorized workflow execution. This involves assessing exposure in WordPress environments using the plugin and implementing compensating controls to monitor and restrict access to form workflow executions.
Recommended defensive actions
- Verify and update the Bit Form plugin to the latest version.
- Assess exposure in WordPress environments using the plugin.
- Implement compensating controls to monitor and restrict access to form workflow executions.
- Monitor for suspicious workflow executions and adjust security settings as necessary.
- Review relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The vulnerability is attributed to a logic flaw in the nonce verification of the triggerWorkFlow function in the Bit Form plugin. The security check only blocks requests when both the nonce verification fails and the user is logged in, allowing unauthenticated attackers to potentially trigger integrations.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-14901 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-14901
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-14901 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-14901
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/bit-form/tags/2.21.6/includes/Frontend/Ajax/FrontendAjax.php
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.