What is CVE-2026-15006?
CVE-2026-15006 is a Directory Traversal vulnerability in the 'Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation' WordPress plugin, affecting versions up to and including 2.9.0. It allows unauthenticated attackers to read arbitrary file contents on the server via the processAttachment function. Immediate plugin update is recommended.
Azərbaycanca: CVE-2026-15006, 'Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation' WordPress plaginində 2.9.0 və daha əvvəlki versiyalara təsir edən Directory Traversal zəifliyidir. Bu, təsdiqlənməmiş hücumçulara processAttachment funksiyası vasitəsilə serverdəki ixtiyari faylların məzmununu oxumağa imkan verir. Plaginin dərhal ən son versiyaya yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Which WordPress plugin is affected by CVE-2026-15006?
This vulnerability affects the 'Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation' plugin.
What can an attacker achieve through CVE-2026-15006?
Unauthenticated attackers can read arbitrary file contents on the server via the processAttachment function.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.