VYPR

Wp Attachments

by WordPress

Source repositories

CVEs (3)

  • CVE-2025-5082MedMay 28, 2025
    risk 0.40cvss 6.1epss 0.01

    The WP Attachments plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘attachment_id’ parameter in all versions up to, and including, 5.0.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

  • CVE-2025-62888MedDec 31, 2025
    risk 0.35cvss 5.4epss 0.00

    Missing Authorization vulnerability in Marco Milesi WP Attachments wp-attachments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Attachments: from n/a through <= 5.2.

  • CVE-2025-11692MedOct 15, 2025
    risk 0.34cvss 5.3epss 0.00

    The Zip Attachments plugin for WordPress is vulnerable to unauthorized loss of data due to a missing authorization and capability checks on the download.php file in all versions up to, and including, 1.6. This makes it possible for unauthenticated attackers to delete arbitrary files from the current wp_upload_dir directory.