CVE-2026-16573: Bit Form < 3.2.0 - Unauthenticated Stored XSS via SVG Signature Upload
The Bit Form WordPress plugin before 3.2.0 does not sanitize an uploaded signature image before storing it, allowing unauthenticated attackers to upload a crafted SVG file containing JavaScript that executes when the file is viewed, leading to Stored Cross-Site Scripting.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16573?
CVE-2026-16573 has a risk rating of 48, indicating a moderate security vulnerability.
How do I fix CVE-2026-16573?
To fix CVE-2026-16573, update the Bit Form WordPress plugin to version 3.2.0 or later.
What type of vulnerability is CVE-2026-16573?
CVE-2026-16573 is an Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability due to improper handling of SVG file uploads.
Who is affected by CVE-2026-16573?
Anyone using the Bit Form WordPress plugin version prior to 3.2.0 is affected by CVE-2026-16573.
What could an attacker do with CVE-2026-16573?
An attacker could upload a malicious SVG file that executes JavaScript, potentially compromising users when the file is viewed.