VYPR

Zip Attachments

by Zip Attachments Project

CVEs (1)

  • CVE-2015-4694HigJan 8, 2016
    risk 0.59cvss 8.6epss 0.33

    Directory traversal vulnerability in download.php in the Zip Attachments plugin before 1.5.1 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the za_file parameter.