CVE-2026-13693
MEDIUMBit Form < 3.1.0 - Unauthenticated Arbitrary File Read via Path Traversal
Title source: cnaDescription
The Bit Form WordPress plugin before 3.1.0 does not restrict a form file-field value to a safe path before reading the file and attaching it to a notification email, allowing unauthenticated attackers to read arbitrary server files such as the WordPress configuration file.
References (1)
Core 1
Core References
Exploit exploit
vdb-entry
technical-description
https://wpscan.com/vulnerability/3a01cd45-1d36-4e36-aca8-947353c474a7/
Scores
CVSS v3
5.9
EPSS
0.0028
EPSS Percentile
20.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-22
Status
published
Products (1)
None/Bit Form
< 3.1.0
Published
Jul 21, 2026
Tracked Since
Jul 21, 2026