Directory Traversal Vulnerability in Bit Integrations Plugin for WordPress
CVE-2026-15006
7.5HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 1 August 2026
What is CVE-2026-15006?
The Bit Integrations plugin for WordPress, used for various integrations including Form Integration and Email Automation, has a security flaw that allows unauthenticated users to exploit a directory traversal vulnerability in the processAttachment function. This vulnerability permits attackers to read arbitrary files from the server, which may include sensitive data, potentially compromising the security of the entire site.
Affected Version(s)
Bit integrations β Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation 0 <= 2.9.0