VYPR

Zip Attachments

by WordPress

CVEs (4)

  • CVE-2015-4694HigJan 8, 2016
    risk 0.57cvss 8.6epss 0.16

    Directory traversal vulnerability in download.php in the Zip Attachments plugin before 1.5.1 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the za_file parameter.

  • CVE-2015-4704HigMay 23, 2017
    risk 0.49cvss 7.5epss 0.05

    Directory traversal vulnerability in the Download Zip Attachments plugin 1.0 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the File parameter to download.php.

  • CVE-2025-11701MedOct 15, 2025
    risk 0.34cvss 5.3epss 0.00

    The Zip Attachments plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check as well as missing post status validation in the za_create_zip_callback function in all versions up to, and including, 1.6. This makes it possible for…

  • CVE-2025-11692MedOct 15, 2025
    risk 0.34cvss 5.3epss 0.00

    The Zip Attachments plugin for WordPress is vulnerable to unauthorized loss of data due to a missing authorization and capability checks on the download.php file in all versions up to, and including, 1.6. This makes it possible for unauthenticated attackers to delete arbitrary…