Junglewise Threat Intelligence

CVE-2026-39070: WordPress Bit Assist Stored XSS in Call-To-Action

CVE-2026-39070 · Severity: medium · CVSS 4.8 · Published 2026-08-28

Executive brief

Bit Assist is a WordPress plugin used to create interactive widgets and content blocks on websites. A stored cross-site scripting vulnerability in the Call-To-Action feature allows administrators to inadvertently inject malicious JavaScript code that executes when other users visit the site, potentially redirecting them to malicious sites or compromising their accounts.

Technical details

The vulnerability is a Stored Cross-Site Scripting (XSS) flaw in the Call-To-Action form field of the Bit Assist WordPress plugin before version 1.7.2. An authenticated attacker with administrator privileges can inject arbitrary JavaScript payloads into the vulnerable field; the payload is then stored in the database and executed in the browsers of all unauthenticated users who visit the affected pages, without sanitization or encoding. This allows an attacker to steal session tokens, redirect users, or deface content. The vulnerability requires administrator access to exploit, but affects all site visitors. A patch is available in version 1.7.2.

Affected products

  • Bit Assist Bit Assist before 1.7.2

Timeline

  • 2026-08-28: disclosed
  • 2026: patched: Fixed in version 1.7.2

References