PT-2026-50836 · WordPress · Bit Integrations

·

CVE-2026-11989

·

Published

2026-06-19

·

Updated

2026-06-23

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation versions prior to 2.8.8
Description An issue exists where unauthenticated attackers can perform Server-Side Request Forgery (SSRF), a flaw that allows a server to be coerced into making requests to an unintended location. This can be used to query or modify information from internal services. The issue occurs via the upload attachment function. Exploitation requires a form integration to be configured with a field mapped to a WooCommerce product image, product gallery, downloadable files, or Google Contacts attachment field.
Recommendations Update to a version newer than 2.8.7.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-11989

Affected Products

Bit Integrations