CVE-2026-13694 UNKNOWN

CVE-2026-13694

Published: 2026-07-21

Description

The Bit Form WordPress plugin before 3.1.0 does not properly validate its workflow-trigger token once the associated transient has expired, allowing unauthenticated attackers to re-trigger a form's configured workflow actions such as notification emails and integrations.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…