{"id":"CVE-2025-15669","title":"The Bit Form  WordPress plugin before 3.1.4 does not sanitise one of its conversational-form display settings before rendering it on the public-facing form, allowing high-privilege users (such as administrators, who do not hold the unfil…","summary":"The Bit Form  WordPress plugin before 3.1.4 does not sanitise one of its conversational-form display settings before rendering it on the public-facing form, allowing high-privilege users (such as administrators, who do not hold the unfil…","severity":"none","published":"2026-08-01","updated":"2026-08-01","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-15669","references":[{"url":"https://wpscan.com/vulnerability/69800fa9-4fbd-489c-8759-96df745d77d6/","label":"contact@wpscan.com"}],"tags":["nvd"],"epss":0.00168,"epssPercentile":0.06545,"ingestedAt":"2026-08-02T01:16:32.170Z","slug":"CVE-2025-15669","body":"## Overview\n\nThe Bit Form  WordPress plugin before 3.1.4 does not sanitise one of its conversational-form display settings before rendering it on the public-facing form, allowing high-privilege users (such as administrators, who do not hold the unfiltered_html capability on multisite) to store JavaScript that executes in the browser of any visitor who views the form.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}