WordPress Plugin Vulnerabilities

Bit Assist < 1.8.2 - Unauthenticated Arbitrary File Upload via Response Endpoint

Description

The plugin does not validate the type, extension, content, or size of files submitted to its public response endpoint and stores them under the uploads directory, so an unauthenticated user can upload arbitrary files. The original extension is discarded (files are stored under a bare UUID), so this does not yield code execution or stored XSS; impact is bounded to disk consumption and content hosting. The storing path requires the channel's response storage or mail-forwarding to be configured.

Proof of Concept

Affects Plugins

Fixed in 1.8.2

References

Miscellaneous

Original Researcher
Vaibhav Narkhede
Submitter
Vaibhav Narkhede
Verified
Yes

Timeline

Publicly Published
2026-07-27 (about 8 days ago)
Added
2026-07-27 (about 7 days ago)
Last Updated
2026-07-27 (about 7 days ago)

Other