PT-2026-50836 · WordPress · Bit Integrations
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation versions prior to 2.8.8
Description
An issue exists where unauthenticated attackers can perform Server-Side Request Forgery (SSRF), a flaw that allows a server to be coerced into making requests to an unintended location. This can be used to query or modify information from internal services. The issue occurs via the
upload attachment function. Exploitation requires a form integration to be configured with a field mapped to a WooCommerce product image, product gallery, downloadable files, or Google Contacts attachment field.Recommendations
Update to a version newer than 2.8.7.
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bit Integrations