High severity8.6NVD Advisory· Published Jan 8, 2016· Updated May 6, 2026
CVE-2015-4694
CVE-2015-4694
Description
Directory traversal vulnerability in download.php in the Zip Attachments plugin before 1.5.1 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the za_file parameter.
Affected products
1- cpe:2.3:a:zip_attachments_project:zip_attachments:*:*:*:*:*:wordpress:*:*Range: <=1.5
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- wordpress.org/plugins/zip-attachments/changelog/nvdPatchVendor Advisory
- www.openwall.com/lists/oss-security/2015/06/12/4nvdExploit
- www.openwall.com/lists/oss-security/2015/06/21/2nvdExploit
- www.vapid.dhs.org/advisory.phpnvdExploit
- www.securityfocus.com/bid/75211nvd
- wordpress.org/support/topic/zip-attachments-wordpress-plugin-v114-arbitrary-file-download-vulnerabilitynvd
- wpvulndb.com/vulnerabilities/8047nvd
News mentions
0No linked articles in our index yet.