Bitapps

Bit Assist

7 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.06%
  • Veröffentlicht 24.12.2025 13:10:45
  • Zuletzt bearbeitet 20.01.2026 15:19:50

Missing Authorization vulnerability in Bit Apps Bit Assist bit-assist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bit Assist: from n/a through <= 1.5.11.

  • EPSS 0.55%
  • Veröffentlicht 01.04.2025 06:15:52
  • Zuletzt bearbeitet 01.04.2025 20:26:11

Path Traversal vulnerability in Bit Apps Bit Assist allows Path Traversal. This issue affects Bit Assist: from n/a through 1.5.4.

  • EPSS 0.25%
  • Veröffentlicht 15.02.2025 13:15:28
  • Zuletzt bearbeitet 24.02.2025 12:36:46

Bit Assist plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.5.2 via the fileID Parameter. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of ...

  • EPSS 0.24%
  • Veröffentlicht 14.02.2025 11:15:10
  • Zuletzt bearbeitet 25.02.2025 03:42:52

Bit Assist plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in all versions up to, and including, 1.5.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existin...

  • EPSS 0.32%
  • Veröffentlicht 14.02.2025 11:15:09
  • Zuletzt bearbeitet 25.02.2025 04:01:52

Bit Assist plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.5.2 via the downloadResponseFile() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to rea...

  • EPSS 0.12%
  • Veröffentlicht 29.12.2023 11:15:09
  • Zuletzt bearbeitet 21.11.2024 08:37:58

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bit Assist Chat Widget: WhatsApp Chat, Facebook Messenger Chat, Telegram Chat Bubble, Line Messenger, Live Chat Support Chat Button, WeChat, SMS, Ca...

Exploit
  • EPSS 0.1%
  • Veröffentlicht 21.08.2023 17:15:49
  • Zuletzt bearbeitet 05.05.2025 16:15:46

The Bit Assist WordPress plugin before 1.1.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed...