---
id: CVE-2026-15006
title: >-
  The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS &
  Email Automation plugin for WordPress is vulnerable to Directory Traversal in
  all versions up to, and including, 2.9.0 via the processAttachment function
summary: >-
  The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS &
  Email Automation plugin for WordPress is vulnerable to Directory Traversal in
  all versions up to, and including, 2.9.0 via the processAttachment function.
  This ma…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-22
published: '2026-08-01'
updated: '2026-08-01'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-15006'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/bit-integrations/tags/2.8.11/backend/Actions/Mail/MailController.php#L123
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/bit-integrations/tags/2.8.11/backend/Actions/Mail/MailController.php#L59
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/bit-integrations/tags/2.8.11/backend/Triggers/CF7/CF7Controller.php#L127
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/bit-integrations/tags/2.8.11/backend/Triggers/CF7/Hooks.php#L11
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/bit-integrations/tags/2.9.0/backend/Actions/Mail/MailController.php#L123
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/bit-integrations/tags/2.9.0/backend/Actions/Mail/MailController.php#L59
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/bit-integrations/tags/2.9.0/backend/Triggers/CF7/CF7Controller.php#L127
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/bit-integrations/tags/2.9.0/backend/Triggers/CF7/Hooks.php#L11
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/changeset?reponame=&old=3605525%40bit-integrations&new=3605525%40bit-integrations
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/9b00da60-7d2d-467e-ab58-0bb4af0cbda5?source=cve
    label: security@wordfence.com
tags:
  - nvd
epss: 0.0124
epssPercentile: 0.67839
ingestedAt: '2026-08-02T00:16:16.480Z'
---

## Overview

The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.0 via the processAttachment function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
