← WordPress Vulnerabilities
WordPress security by component

Bit Integrations

Bit Integrations is a WordPress component with 3 published CVE records in this archive. The latest tracked vulnerability was published Aug 01, 2026; the highest published CVSS base score is 7.5.

Plugin slug: bit-integrations

CVE-2026-15006: Bit Integrations attachment handling lets visitors read server files

Bit Integrations through 2.9.0 passes attacker-influenced attachment paths into MailController::processAttachment() without keeping path resolution inside an approved attachment directory. An unauthenticated visitor can use directory-traversal input to make the function read arbitrary server files, exposing data available to the WordPress process such as configuration secrets. The published record links the Mail action and Contact Form 7 trigger path but does not disclose the exact public request, attachment parameter name or traversal encoding.

PublishedAug 01, 2026
Known safe version2.9.1
Published vulnerabilities for bit-integrations
Safe version
Aug 01, 2026 CVE-2026-15006
Bit Integrations attachment handling lets visitors read server files
Bit Integrations through 2.9.0 passes attacker-influenced attachment paths into MailController::processAttachment() without keeping path resolution inside an approved attachment directory. An unauthenticated visitor can use directory-traversal input to make the function read arbitrary server files, exposing data available to the WordPress process such as configuration secrets. The published record links the Mail action and Contact Form 7 trigger path but does not disclose the exact public request, attachment parameter name or traversal encoding.
2.9.1
CVE7.5
NVDPending
Jun 19, 2026 CVE-2026-11989
Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation: Server-side request forgery
Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation is affected by server-side request forgery. The vulnerable path is reachable without authentication. The vulnerable server can be induced to make attacker-selected network requests. The published affected range is <= 2.8.7.
> 2.8.7
CVE6.5
NVDPending
Mar 27, 2025 CVE-2025-30884
Bit Integrations: An open redirect
Bit Integrations is affected by an open redirect. Exposure depends on how the affected operation is made reachable by the site. A crafted link can redirect visitors from the trusted site to an attacker-controlled destination.
See mitigation notes
CVE4.7
NVDPending