{"id":"CVE-2026-16573","published":"2026-08-05T07:16:35.683","lastModified":"2026-08-05T15:16:37.830","description":"The Bit Form  WordPress plugin before 3.2.0 does not sanitize an uploaded signature image before storing it, allowing unauthenticated attackers to upload a crafted SVG file containing JavaScript that executes when the file is viewed, leading to Stored Cross-Site Scripting.","cvssScore":7.5,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","cwes":["CWE-79"],"vendors":[],"products":[],"references":[{"url":"https://wpscan.com/vulnerability/a102e6ba-02f3-46cf-b496-f129ea3d9c8f/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw allows unauthenticated attackers to upload a malicious SVG file containing JavaScript, leading to Stored Cross-Site Scripting (XSS). This matters because it can enable arbitrary code execution in users' browsers when they view the affected site.","exploitability":"Exploitation is relatively easy as no authentication is required. Attackers need access to the WordPress admin panel or file upload functionality.","blast_radius":"If exploited, this could impact all users viewing the page containing the malicious SVG, potentially leading to data theft or further attacks via injected scripts.","remediation":"Update Bit Form WordPress plugin to version 3.2.0 or later immediately.","tags":["xss","wp-plugin","unauth","svg"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-08-11T06:57:25.226Z"}}