plugin

Bfg Tools Extension Zipper Vulnerabilities

1 known security issue reported for the Bfg Tools Extension Zipper WordPress plugin. Most recent disclosed Feb 13, 2026.

1 medium

Running Bfg Tools Extension Zipper on your site? Check whether your installed version is affected.

Scan your site free

BFG Tools – Extension Zipper <= 1.0.7 - Authenticated (Administrator+) Path Traversal via 'first_file' Parameter

medium

The BFG Tools – Extension Zipper plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.0.7. This is due to insufficient input validation on the user-supplied `first_file` parameter in the `zip()` function. This makes it possible for authenticated attackers, with Administrator-leve...

CVSS:
4.9
Affected:
up to 1.0.7
Fixed in:
1.0.8
Disclosed:
Feb 13, 2026

CVE-2025-13681 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database