CVE-2026-11989
medium
📛 Threat Title
Bit integrations <= 2.8.7 - Unauthenticated Server-Side Request Forgery via Form Field Upload Mapping
Description
The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.8.7 via the upload_attachment. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. Exploitation requires a form integration to be configured with a field mapped to a WooCommerce product image, product gallery, downloadable files, or Google Contacts attachment field, which is a default use case for these integrations. Affected software — plugin: Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation (affected: *-2.8.7). CVSS 6.5 (Medium) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N.
Remediations (3)
-
Wordfence remediation: Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email AutomationWordfence
Update to version 2.8.8, or a newer patched version
-
Wordfence remediation: Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email AutomationWordfence
Update to version 2.8.8, or a newer patched version
-
Wordfence remediation: Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email AutomationWordfence
Update to version 2.8.8, or a newer patched version
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
cve
CVE-2026-11989
IOC database
- Type
- cve
- Value
CVE-2026-11989- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Bit integrations <= 2.8.7 - Unauthenticated Server-Side Request Forgery via Form Field Upload Mapping
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (3)
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.