plugin

Bit Integrations Vulnerabilities

4 known security issues reported for the Bit Integrations WordPress plugin. Most recent disclosed Jul 31, 2026.

2 high 1 medium

Running Bit Integrations on your site? Check whether your installed version is affected.

Scan your site free

Bit integrations <= 2.9.0 - Unauthenticated Arbitrary File Read via Optional CF7 File Field

high

The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.0 via the processAttachment function. This makes it possible for unauthenticated attackers to read the contents of arbitrary fil...

CVSS:
7.5
Affected:
up to 2.9.0
Fixed in:
2.9.1
Disclosed:
Jul 31, 2026

CVE-2026-15006 on NVD →

Bit integrations <= 2.8.7 - Unauthenticated Server-Side Request Forgery via Form Field Upload Mapping

medium

The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.8.7 via the upload_attachment. This makes it possible for unauthenticated attackers to make web requests to arbitrary loca...

CVSS:
6.5
Affected:
up to 2.8.7
Fixed in:
2.8.8
Disclosed:
Jun 18, 2026

CVE-2026-11989 on NVD →

Bit Integrations <= 2.4.10 - Open Redirect

high

The Webhook Automator & Contact Form Integration to Automate 280+ Platforms – Bit Integrations plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 2.4.10. This is due to insufficient validation on a redirect url. This makes it possible for unauthenticated attackers to redirect user...

CVSS:
7.2
Affected:
up to 2.4.10
Fixed in:
2.5.0
Disclosed:
Mar 27, 2025

CVE-2025-30884 on NVD →

Bit integrations &#8211; Easy Automator with no-code automation, integrate Webhook and automate 290+ Platform [bit-integrations] < 2.5.0

unknown

[en] URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Bit Apps Bit Integrations allows Phishing. This issue affects Bit Integrations: from n/a through 2.4.10.

Affected:
up to 2.5.0
Fixed in:
2.5.0
Disclosed:
Mar 27, 2025

CVE-2025-30884 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database