What is CVE-2026-16573?
CVE-2026-16573 allows unauthenticated attackers to upload crafted SVG files with embedded JavaScript due to missing sanitization of signature images in the Bit Form WordPress plugin before version 3.2.0, leading to Stored Cross-Site Scripting when the file is viewed. Affected users should immediately update to version 3.2.0 or later.
Azərbaycanca: CVE-2026-16573, Bit Form WordPress plaginin 3.2.0-dən əvvəlki versiyalarında imza şəklini sanitizasiya etmədən saxlaması səbəbindən autentifikasiya olunmamış hücumçuların zərərli SVG faylları yükləyərək Stored Cross-Site Scripting (XSS) hücumu həyata keçirməsinə imkan verir. Təsirə məruz qalan istifadəçilər plagini dərhal 3.2.0 və ya daha yuxarı versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Does exploiting CVE-2026-16573 require the attacker to be authenticated?
No, this vulnerability can be exploited by unauthenticated attackers.
To which version should the Bit Form WordPress plugin be updated to mitigate CVE-2026-16573?
The plugin should be updated to version 3.2.0 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.