CVE-2026-39070: WordPress plugin (Bit Assist) vulnerability
Published Aug 28, 2026
·Updated
WordPress plugin (Bit Assist) before 1.7.2 is affected by Stored Cross-Site Scripting in Call-To-Action feature. An authenticated attacker with the privileged role (admin) can exploit this to redirect user to malicious site or control the account.
Affected Software
1 affected component
WordPress plugin (Bit Assist)<1.7.2
Event History
Aug 28, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
Which deployments are exposed to this issue?
Deployments using the Bit Assist WordPress plugin at a version before 1.7.2 are affected, specifically through its Call-To-Action feature.
2
What access does an attacker need to exploit it?
The attacker must be authenticated and have the WordPress administrator role. The provided information does not indicate that lower-privileged users or unauthenticated visitors can exploit it.
3
What could exploitation allow?
Successful exploitation can store cross-site scripting payloads that may redirect users to a malicious site or enable control of an account.