MEDIUM
Bit Assist
CVE published 2026-08-28
CVE-2026-39070
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-28T20:17:28.560Z and has not been modified since then. The Bit Assist plugin for WordPress before version 1.7.2 is affected by a Stored Cross-Site Scripting vulnerability in the Call-To-Action feature. An authenticated attacker with the privileged role (admin) can exploit this to redirect users to a [truncated]