BFG Tools – Extension Zipper <= 1.0.7 - Authenticated (Administrator+) Path Traversal via 'first_file' Parameter
mediumThe BFG Tools – Extension Zipper plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.0.7. This is due to insufficient input validation on the user-supplied `first_file` parameter in the `zip()` function. This makes it possible for authenticated attackers, with Administrator-leve...
- CVSS:
- 4.9
- Affected:
- up to 1.0.7
- Fixed in:
- 1.0.8
- Disclosed:
- Feb 13, 2026