WordPress · Bit Integrations · CVE-2026-11989
**Name of the Vulnerable Software and Affected Versions**
Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation versions prior to 2.8.8
**Description**
An issue exists where unauthenticated attackers can perform Server-Side Request Forgery (SSRF), a flaw that allows a server to be coerced into making requests to an unintended location. This can be used to query or modify information from internal services. The issue occurs via the `upload attachment` function. Exploitation requires a form integration to be configured with a field mapped to a WooCommerce product image, product gallery, downloadable files, or Google Contacts attachment field.
**Recommendations**
Update to a version newer than 2.8.7.