WordPress · Bit Form · CVE-2026-13693
**Name of the Vulnerable Software and Affected Versions**
Bit Form versions prior to 3.1.0
**Description**
An issue exists where the plugin fails to restrict a form file-field value to a safe path before reading the file and attaching it to a notification email. This allows unauthenticated attackers to perform a path traversal attack to read arbitrary server files, such as the WordPress configuration file.
**Recommendations**
Update Bit Form to version 3.1.0 or later.