CVE-2026-13693
Description
The Bit Form WordPress plugin before 3.1.0 does not restrict a form file-field value to a safe path before reading the file and attaching it to a notification email, allowing unauthenticated attackers to read arbitrary server files such as the WordPress configuration file.
Metadata
Severity & Metrics
No CVSS data available.
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| Unknown | Bit Form | — | 0 < 3.1.0 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| — | cna | CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |