Zip Attachments <= 1.6 - Missing Authorization to Unauthenticated Private And Password-Protected Posts Attachment Disclosure
medium
The Zip Attachments plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check as well as missing post status validation in the za_create_zip_callback function in all versions up to, and including, 1.6. This makes it possible for unauthenticated attackers to download attachments...
- CVSS:
- 5.3
- Affected:
- up to 1.6
- Fix:
- No patched version reported
- Disclosed:
- Oct 14, 2025
CVE-2025-11701 on NVD →
Zip Attachments <= 1.6 - Missing Authorization to Limited File Deletion
medium
The Zip Attachments plugin for WordPress is vulnerable to unauthorized loss of data due to a missing authorization and capability checks on the download.php file in all versions up to, and including, 1.6. This makes it possible for unauthenticated attackers to delete arbitrary files from the current wp_upload_dir direc...
- CVSS:
- 5.3
- Affected:
- up to 1.6
- Fix:
- No patched version reported
- Disclosed:
- Oct 14, 2025
CVE-2025-11692 on NVD →
Zip Attachments <= 1.5 - Directory Traversal
high
Directory traversal vulnerability in download.php in the Zip Attachments plugin before 1.5.1 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the za_file parameter.
- CVSS:
- 8.6
- Affected:
- up to 1.5
- Fixed in:
- 1.5.1
- Disclosed:
- Jun 12, 2015
CVE-2015-4694 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database