CVE-2024-13451

Contact Form by Bit Form <= 2.17.5 - Unauthenticated Sensitive Information Exposure

The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.17.4 via file uploads due to insufficient directory listing prevention and lack of randomization of file names. This makes it possible for unauthenticated attackers to extract sensitive data including files uploaded via a form. The vulnerability was partially patched in version 2.17.5.


We have discovered 243 live websites that are affected by CVE-2024-13451.

Run a Free Instant Scan




Affected Software

Product  Bit Form
Category Wordpress Plugins
Vulnerable Domains243 live websites (36% of Bit Form install base)
Vulnerable Versions
  • from 0 through 2.17.5
Vulnerable Versions Count46 versions ( 75% of all versions)


Common Weakness Enumeration

CWE-200 Exposure of Sensitive Information to an Unauthorized Actor



Details

  • Published - Jul 2, 2025
  • Updated - Jul 2, 2025

Credits

  • Tim Coen (finder)

Website Distribution by Country

Number of websites using CVE-2024-13451
United States79 websites



France23 websites
Germany21 websites
Italy14 websites
Russia14 websites
Cyprus12 websites
Czech Republic11 websites
GB11 websites
Australia7 websites
Brazil5 websites

Website Distribution by TLD

Number of websites using CVE-2024-13451
.com78 websites
.com.au20 websites
.ru13 websites
.it12 websites
.org11 websites
.cz11 websites
.co.uk10 websites
.com.br8 websites
.net7 websites
.de6 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-13451

Top websites that are affected by CVE-2024-13451. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********.com France**,***
***************.com United States***,***
*********.tv United States***,***
**********.com United States*,***,***
********.**.kr United States*,***,***
*************.ca United States*,***,***
*************************.net Cyprus*,***,***
*********************.***.br Chile*,***,***
*****.org United States*,***,***
****.io Germany*,***,***
See full domain list

FAQ

CVE-2024-13451 is Exposure of Sensitive Information to an Unauthorized Actor in Bit Form
A total of 243 websites have been identified as vulnerable to CVE-2024-13451, based on global website indexing conducted by WebTechSurvey.
The Bit Form is affected by the CVE-2024-13451 vulnerability.
Bit Form versions up to and including 2.17.5 are vulnerable to CVE-2024-13451.