What is CVE-2025-15669?
This flaw arises from a lack of sanitization in the conversational-form display settings of the Bit Form WordPress plugin before version 3.1.4. High-privilege users (e.g., administrators without the unfiltered_html capability on multisite) can inject stored XSS. Update the plugin to the latest version.
Azərbaycanca: Bu boşluq Bit Form WordPress plaginində (3.1.4 öncəsi versiyalar) söhbət formasının göstərilmə parametrlərində sanitizasiya çatışmazlığından qaynaqlanır. Yüksək səlahiyyətli istifadəçilər (məsələn, multisite şəbəkələrdə "unfiltered_html" icazəsi olmayan adminlər) XSS hücumu keçirə bilər. Plaqini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
What issue does CVE-2025-15669 relate to?
This flaw arises from a lack of sanitization in the conversational-form display settings of the Bit Form WordPress plugin.
How to protect against CVE-2025-15669?
Update the Bit Form plugin to the latest version (3.1.4 or later).
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.