CVE-2026-15006
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Summary
The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.0 via the processAttachment function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| bitpressadmin | Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation | 0 <= 2.9.0 | affected |
Weaknesses
- CWE-22: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
References
- https://www.wordfence.com/threat-intel/vulnerabilities/id/9b00da60-7d2d-467e-ab58-0bb4af0cbda5?source=cve
- https://plugins.trac.wordpress.org/browser/bit-integrations/tags/2.9.0/backend/Actions/Mail/MailController.php#L123
- https://plugins.trac.wordpress.org/browser/bit-integrations/tags/2.9.0/backend/Actions/Mail/MailController.php#L59
- https://plugins.trac.wordpress.org/browser/bit-integrations/tags/2.9.0/backend/Triggers/CF7/CF7Controller.php#L127
- https://plugins.trac.wordpress.org/browser/bit-integrations/tags/2.9.0/backend/Triggers/CF7/Hooks.php#L11
- https://plugins.trac.wordpress.org/browser/bit-integrations/tags/2.8.11/backend/Actions/Mail/MailController.php#L123
- https://plugins.trac.wordpress.org/browser/bit-integrations/tags/2.8.11/backend/Actions/Mail/MailController.php#L59
- https://plugins.trac.wordpress.org/browser/bit-integrations/tags/2.8.11/backend/Triggers/CF7/CF7Controller.php#L127
- https://plugins.trac.wordpress.org/browser/bit-integrations/tags/2.8.11/backend/Triggers/CF7/Hooks.php#L11
- https://plugins.trac.wordpress.org/changeset?reponame=&old=3605525%40bit-integrations&new=3605525%40bit-integrations
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.