
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-25418 is a SQL Injection vulnerability in the Bit Apps Bit Form WordPress plugin, classified under CWE-89 (Improper Neutralization of Special Elements used in an SQL Command). It affects all versions of the plugin up to and including 2.21.10. The vulnerability was published on February 19, 2026, and carries a CVSS v3.1 base score of 7.6 (High) (Feedly, Wordfence).
The vulnerability stems from insufficient sanitization of user-supplied input before it is incorporated into SQL queries within the Bit Form plugin (CWE-89). An authenticated attacker with high privileges (e.g., administrator-level access) can craft malicious SQL statements passed through plugin parameters, causing the database to execute unintended commands. The changed scope (S:C) in the CVSS vector indicates the impact can extend beyond the plugin itself to the underlying WordPress database. No public proof-of-concept code has been identified at this time (Feedly, Patchstack).
Successful exploitation primarily threatens confidentiality, allowing an attacker to extract sensitive data from the WordPress database — including user credentials, form submissions, and site configuration — with high confidentiality impact. Availability is marginally affected (low impact), while integrity is not directly impacted per the CVSS assessment. Because the scope is marked as changed, the attack can potentially reach data or resources beyond the plugin's own database tables, increasing the risk of broader site compromise (Feedly).
Exploitation requires network access and high-privilege authentication (e.g., WordPress administrator), which limits opportunistic exploitation but does not eliminate risk in environments with compromised admin accounts or insider threats. The EPSS score is approximately 0.021% (0.000210), indicating a currently low probability of widespread exploitation. No in-the-wild exploitation, threat actor attribution, or CISA KEV catalog listing has been reported as of the latest available data (Feedly).
' UNION SELECT user_login, user_pass FROM wp_users-- -) into the vulnerable parameter to extract data from the WordPress database.', --, UNION, SELECT) in query parameters or POST body.UNION SELECT, INFORMATION_SCHEMA, or wp_users table access originating from the WordPress application user.Users should update the Bit Form plugin to a version beyond 2.21.10 as soon as a patched release is made available by Bit Apps. In the interim, administrators should restrict access to the WordPress admin panel using IP allowlisting or two-factor authentication to reduce the attack surface, given that exploitation requires high-privilege credentials. Monitoring database query logs for anomalous SQL patterns is also recommended as a detective control (Patchstack, Feedly).
Wordfence included this vulnerability in their weekly WordPress vulnerability report for the period of January 26 – February 1, 2026, highlighting it as part of broader plugin security tracking (Wordfence). The Hacker Wire also published a brief notice on the CVE, and it was catalogued by Patchstack and VulDB shortly after disclosure. No significant researcher commentary or broader media coverage has been identified beyond routine vulnerability aggregation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."