Medium 5.3
2025-12-24< 1.6.0
CVE-2025-68596
Minimum safe version
1.6.0
Update to 1.6.0 or later to address 9 fixable vulnerabilities
CVE-2025-68596
CVE-2025-30834
Bit Assist <= 1.5.2 - Authenticated (Subscriber+) SQL Injection via id Parameter
Bit Assist <= 1.5.2 - Path Traversal to Authenticated (Subscriber+) Arbitrary File Read via fileID Parameter
CVE-2024-13791
WordPress Bit Assist Plugin <= 1.1.9 is vulnerable to Cross Site Scripting (XSS)
WordPress Bit Assist Plugin < 1.2 is vulnerable to Cross Site Scripting (XSS)
Bit Assist <= 1.1.9 - Authenticated (Administrator+) Stored Cross-Site Scripting
CVE-2023-3667