WordPress security by component
Bit Integrations
Plugin description
Bit Integrations is a WordPress component with 3 published CVE records in this archive. The latest tracked vulnerability was published Aug 01, 2026; the highest published CVSS base score is 7.5.
Plugin slug:
bit-integrationsLatest vulnerability
CVE-2026-15006: Bit Integrations attachment handling lets visitors read server files
Bit Integrations through 2.9.0 passes attacker-influenced attachment paths into MailController::processAttachment() without keeping path resolution inside an approved attachment directory. An unauthenticated visitor can use directory-traversal input to make the function read arbitrary server files, exposing data available to the WordPress process such as configuration secrets. The published record links the Mail action and Contact Form 7 trigger path but does not disclose the exact public request, attachment parameter name or traversal encoding.
| Safe version |
|
||
|---|---|---|---|
| Aug 01, 2026 |
CVE-2026-15006
Bit Integrations attachment handling lets visitors read server files
Bit Integrations through 2.9.0 passes attacker-influenced attachment paths into MailController::processAttachment() without keeping path resolution inside an approved attachment directory. An unauthenticated visitor can use directory-traversal input to make the function read arbitrary server files, exposing data available to the WordPress process such as configuration secrets. The published record links the Mail action and Contact Form 7 trigger path but does not disclose the exact public request, attachment parameter name or traversal encoding.
|
2.9.1 |
CVE7.5
NVDPending
|
| Jun 19, 2026 |
CVE-2026-11989
Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation: Server-side request forgery
Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation is affected by server-side request forgery. The vulnerable path is reachable without authentication. The vulnerable server can be induced to make attacker-selected network requests. The published affected range is <= 2.8.7.
|
> 2.8.7 |
CVE6.5
NVDPending
|
| Mar 27, 2025 |
CVE-2025-30884
Bit Integrations: An open redirect
Bit Integrations is affected by an open redirect. Exposure depends on how the affected operation is made reachable by the site. A crafted link can redirect visitors from the trusted site to an attacker-controlled destination.
|
See mitigation notes |
CVE4.7
NVDPending
|