plugin

Zip Attachments Vulnerabilities

3 known security issues reported for the Zip Attachments WordPress plugin. Most recent disclosed Oct 14, 2025.

1 high 2 medium

Running Zip Attachments on your site? Check whether your installed version is affected.

Scan your site free

Zip Attachments <= 1.6 - Missing Authorization to Unauthenticated Private And Password-Protected Posts Attachment Disclosure

medium

The Zip Attachments plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check as well as missing post status validation in the za_create_zip_callback function in all versions up to, and including, 1.6. This makes it possible for unauthenticated attackers to download attachments...

CVSS:
5.3
Affected:
up to 1.6
Fix:
No patched version reported
Disclosed:
Oct 14, 2025

CVE-2025-11701 on NVD →

Zip Attachments <= 1.6 - Missing Authorization to Limited File Deletion

medium

The Zip Attachments plugin for WordPress is vulnerable to unauthorized loss of data due to a missing authorization and capability checks on the download.php file in all versions up to, and including, 1.6. This makes it possible for unauthenticated attackers to delete arbitrary files from the current wp_upload_dir direc...

CVSS:
5.3
Affected:
up to 1.6
Fix:
No patched version reported
Disclosed:
Oct 14, 2025

CVE-2025-11692 on NVD →

Zip Attachments <= 1.5 - Directory Traversal

high

Directory traversal vulnerability in download.php in the Zip Attachments plugin before 1.5.1 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the za_file parameter.

CVSS:
8.6
Affected:
up to 1.5
Fixed in:
1.5.1
Disclosed:
Jun 12, 2015

CVE-2015-4694 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database