plugin

Bit Assist Vulnerabilities

17 known security issues reported for the Bit Assist WordPress plugin. Most recent disclosed Jul 27, 2026.

1 critical 7 medium

Running Bit Assist on your site? Check whether your installed version is affected.

Scan your site free

Bit Assist <= 1.8.1 - Unauthenticated Arbitrary File Upload

critical

The Bit Assist plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 1.8.1. This is due to missing file type validation in the file upload handler, allowing any file extension to be stored without checking against a blocklist or WordPress MIME allowlist. This makes it possible fo...

CVSS:
9.8
Affected:
up to 1.8.1
Fixed in:
1.8.2
Disclosed:
Jul 27, 2026

CVE-2026-16548 on NVD →

Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat &#8211; Bit Assist [bit-assist] <= 1.5.11 (unfixed)

unknown

[en] Missing Authorization vulnerability in Bit Apps Bit Assist bit-assist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bit Assist: from n/a through <= 1.5.11.

Affected:
up to 1.5.11
Fix:
No patched version reported
Disclosed:
Dec 24, 2025

CVE-2025-68596 on NVD →

Bit Assist <= 1.5.11 - Missing Authorization

medium

The Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat – Bit Assist plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.5.11. This makes it possible for unauthenticated attackers to...

CVSS:
5.3
Affected:
up to 1.5.11
Fixed in:
1.6.0
Disclosed:
Dec 19, 2025

CVE-2025-68596 on NVD →

Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat &#8211; Bit Assist [bit-assist] < 1.5.5

unknown

[en] Path Traversal vulnerability in Bit Apps Bit Assist allows Path Traversal. This issue affects Bit Assist: from n/a through 1.5.4.

Affected:
up to 1.5.5
Fixed in:
1.5.5
Disclosed:
Apr 1, 2025

CVE-2025-30834 on NVD →

Bit Assist <= 1.5.4 - Unauthenticated Path Traversal

medium

The Chat Widget: Customer Support Button with SMS Call Button, Click to Chat Messenger, Live Chat Support Chat Button – Bit Assist plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.5.4. This makes it possible for unauthenticated attackers to perform actions on files outside of...

CVSS:
5.8
Affected:
up to 1.5.4
Fixed in:
1.5.5
Disclosed:
Mar 28, 2025

CVE-2025-30834 on NVD →

Bit Assist <= 1.5.2 - Path Traversal to Authenticated (Subscriber+) Arbitrary File Read via fileID Parameter

medium

Bit Assist plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.5.2 via the fileID Parameter. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information...

CVSS:
6.5
Affected:
up to 1.5.2
Fixed in:
1.5.3
Disclosed:
Feb 14, 2025

CVE-2025-0822 on NVD →

Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat &#8211; Bit Assist [bit-assist] < 1.5.3

unknown

[en] Bit Assist plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.5.2 via the downloadResponseFile() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to read the contents of arbitrary files on the server, which can contai...

Affected:
up to 1.5.3
Fixed in:
1.5.3
Disclosed:
Feb 14, 2025

CVE-2024-13791 on NVD →

Bit Assist <= 1.5.2 - Path Traversal to Authenticated (Administrator+) Arbitrary File Read via downloadResponseFile Function

medium

Bit Assist plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.5.2 via the downloadResponseFile() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to read the contents of arbitrary files on the server, which can contain sen...

CVSS:
4.9
Affected:
up to 1.5.2
Fixed in:
1.5.3
Disclosed:
Feb 13, 2025

CVE-2024-13791 on NVD →

Bit Assist <= 1.5.2 - Authenticated (Subscriber+) SQL Injection via id Parameter

medium

Bit Assist plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in all versions up to, and including, 1.5.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with...

CVSS:
6.5
Affected:
up to 1.5.2
Fixed in:
1.5.3
Disclosed:
Feb 13, 2025

CVE-2025-0821 on NVD →

Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat &#8211; Bit Assist [bit-assist] < 1.2

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bit Assist Chat Widget: WhatsApp Chat, Facebook Messenger Chat, Telegram Chat Bubble, Line Messenger, Live Chat Support Chat Button, WeChat, SMS, Call Button, Customer Support Button with floating Chat Widget allo...

Affected:
up to 1.2
Fixed in:
1.2
Disclosed:
Dec 29, 2023

CVE-2023-51371 on NVD →

Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat &#8211; Bit Assist [bit-assist] < 1.2

unknown

Update the WordPress Bit Assist plugin to the latest available version (at least 1.2). Unknown discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Bit Assist Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads...

Affected:
up to 1.2
Fixed in:
1.2
Disclosed:
Sep 19, 2023

Bit Assist <= 1.1.9 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Bit Assist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 1.1.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary...

CVSS:
4.4
Affected:
up to 1.2
Fixed in:
1.2
Disclosed:
Sep 18, 2023

CVE-2023-51371 on NVD →

Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat &#8211; Bit Assist [bit-assist] < 1.2

unknown

The Bit Assist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 1.1.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary...

Affected:
up to 1.2
Fixed in:
1.2
Disclosed:
Sep 18, 2023

Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat &#8211; Bit Assist [bit-assist] < 1.1.9

unknown

[en] The Bit Assist WordPress plugin before 1.1.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

Affected:
up to 1.1.9
Fixed in:
1.1.9
Disclosed:
Aug 21, 2023

CVE-2023-3667 on NVD →

Bit Assist <= 1.1.8 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Bit Assist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 1.1.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary...

CVSS:
4.4
Affected:
up to 1.1.8
Fixed in:
1.1.9
Disclosed:
Jul 27, 2023

CVE-2023-3667 on NVD →

Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat &#8211; Bit Assist [bit-assist] < 1.5.3

unknown
Affected:
up to 1.5.3
Fixed in:
1.5.3

CVE-2025-0822 on NVD →

Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat &#8211; Bit Assist [bit-assist] < 1.5.3

unknown
Affected:
up to 1.5.3
Fixed in:
1.5.3

CVE-2025-0821 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database