HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2026-15006 — The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email...

·Source: NIST NVD

Updated:

Executive Summary

The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.0 via the processAttachment function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.

Analysis

The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.0 via the processAttachment function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. CVSS Score: 7.5. Published: 2026-08-01T03:16:25.460.

Indicators of Compromise (1)

CVE (1)
CVE-2026-15006
Source Attribution

Originally published by NIST NVD on Aug 1, 2026. Verified by: NIST.

Related Threats