PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-14901 bitpressadmin CVE debrief

The Bit Form – Contact Form Plugin for WordPress is vulnerable to unauthorized workflow execution due to a logic flaw in the nonce verification process. This allows unauthenticated attackers to replay form workflow executions and trigger integrations like webhooks and email notifications if they can obtain the entry ID and log IDs from a legitimate form submission response.

Vendor
bitpressadmin
Product
Bit Form – Custom Contact Form, Multi Step, Conversational Form & Payment Form builder
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-01-07
Original CVE updated
2026-09-30
Advisory published
2026-01-07
Advisory updated
2026-09-30

Who should care

Defenders responsible for WordPress environments using the Bit Form plugin should assess exposure and prioritize updating the plugin to prevent unauthorized workflow execution. This involves verifying the plugin version, monitoring for suspicious activities, and implementing security measures to restrict access to form workflow executions.

Why it matters

The Bit Form plugin vulnerability allows unauthenticated attackers to potentially trigger integrations and replay workflow executions. Defenders should assess exposure, verify and update the plugin, and implement security measures to prevent unauthorized access.

  • Potential unauthorized triggering of integrations like webhooks and email notifications.
  • Possible replay of form workflow executions by unauthenticated attackers.
  • Need for verification of plugin version and exposure in WordPress environments.
  • Requirement for compensating controls to monitor and restrict access to form workflow executions.

Technical summary

The Bit Form – Contact Form Plugin for WordPress is vulnerable to unauthorized workflow execution due to missing authorization in the triggerWorkFlow function. This flaw allows unauthenticated attackers to replay form workflow executions and trigger all configured integrations, including webhooks and email notifications, if they can obtain the entry ID and log IDs from a legitimate form submission response.

Defensive priority

Defenders should prioritize verifying and updating the Bit Form plugin to prevent unauthorized workflow execution. This involves assessing exposure in WordPress environments using the plugin and implementing compensating controls to monitor and restrict access to form workflow executions.

Recommended defensive actions

  • Verify and update the Bit Form plugin to the latest version.
  • Assess exposure in WordPress environments using the plugin.
  • Implement compensating controls to monitor and restrict access to form workflow executions.
  • Monitor for suspicious workflow executions and adjust security settings as necessary.
  • Review relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The vulnerability is attributed to a logic flaw in the nonce verification of the triggerWorkFlow function in the Bit Form plugin. The security check only blocks requests when both the nonce verification fails and the user is logged in, allowing unauthenticated attackers to potentially trigger integrations.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-14901 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-14901

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-14901 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-14901

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/bit-form/tags/2.21.6/includes/Frontend/Ajax/FrontendAjax.php

    [email protected]

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.