SecAlerts
bitapps logo

bitapps

Security Risk Profile

43
/100
medium

Security Risk Score

Comprehensive risk assessment based on 23 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from May 15, 2023 to present

23
Total CVEs
12
Critical+High
0
Exploited
4
Unpatched

Threat Assessment

Avg CVSS
7.1
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
4
Critical/High
Risk Level
43/100
medium

Severity Distribution

Critical
4
High
8
Medium
11
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
8

Age Distribution

Common Weaknesses (CWE)

1
Path Traversal
6
2
XSS
4
3
SQL Injection
3
4
Malicious File Upload
3
5
Infoleak
2

Most Affected Products

1. Bitapps Contact Form Builder Wordpress8
2. Bitapps Bit Form Wordpress6
3. Bitapps Bit Assist Wordpress5
4. Bitapps File Manager Wordpress4
5. Bit Assist Bit Assist3

Recent Vulnerabilities

See more →
CVE-2024-13451
CVSS 7.5high

Contact Form by Bit Form <= 2.17.5 - Unauthenticated Sensitive Information Exposure

7/2/2025
CVE-2025-0822
CVSS 6.5medium

Bit Assist <= 1.5.2 - Path Traversal to Authenticated (Subscriber+) Arbitrary File Read via fileID Parameter

2/15/2025
CVE-2025-0821
CVSS 6.5medium

Bit Assist <= 1.5.2 - Authenticated (Subscriber+) SQL Injection via id Parameter

2/14/2025
CVE-2024-13791
CVSS 4.9medium

Bit Assist <= 1.5.2 - Path Traversal to Authenticated (Administrator+) Arbitrary File Read via downloadResponseFile Function

2/14/2025
CVE-2024-13450
CVSS 6.5medium

Contact Form by Bit Form <= 2.17.4 - Authenticated (Administrator+) Server-Side Request Forgery

1/25/2025🔧 No Patch
CVE-2024-7770
CVSS 8.8EPSS 0%high

Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress <= 6.5.5 - Authenticated (Subscriber+) Arbitrary File Upload

9/10/2024
CVE-2024-7627
CVSS 8.1EPSS 0%high

Bit File Manager 6.0 - 6.5.5 - Unauthenticated Remote Code Execution via Race Condition

9/5/2024
CVE-2024-43251
CVSS 6.5medium

WordPress Bit Form Pro plugin <= 2.6.4 - Authenticated Sensitive Data Exposure vulnerability

8/26/2024🔧 No Patch
CVE-2024-7782
CVSS 8.7EPSS 0%high

Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder 2.0 - 2.13.4 - Authenticater (Administrator+) Arbitrary File Deletion

8/20/2024
CVE-2024-7780
CVSS 7.2EPSS 0%high

Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder 2.0 - 2.13.9 - Authenticated (Administrator+) SQL Injection

8/20/2024

Monitor bitapps in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

bitapps Security Vulnerabilities & Risk Score | 23 CVEs | SecAlerts - SecAlerts