plugin

Zippy Vulnerabilities

10 known security issues reported for the Zippy WordPress plugin. Most recent disclosed Oct 22, 2025.

3 high 2 medium

Running Zippy on your site? Check whether your installed version is affected.

Scan your site free

Zippy [zippy] <= 1.7.0 (unfixed)

unknown

[en] Unrestricted Upload of File with Dangerous Type vulnerability in Gesundheit Bewegt GmbH Zippy zippy allows Using Malicious Files.This issue affects Zippy: from n/a through <= 1.7.0.

Affected:
up to 1.7.0
Fix:
No patched version reported
Disclosed:
Oct 22, 2025

CVE-2025-52758 on NVD →

Zippy [zippy] < 1.6.3

unknown

[en] Missing Authorization vulnerability in Gesundheit Bewegt GmbH Zippy allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Zippy: from n/a through 1.6.2.

Affected:
up to 1.6.3
Fixed in:
1.6.3
Disclosed:
Dec 13, 2024

CVE-2023-34381 on NVD →

Zippy <= 1.7.0 - Authenticated (Editor+) Arbitrary File Upload

high

The Zippy plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 1.7.0. This makes it possible for authenticated attackers, with editor-level access and above, to upload arbitrary files on the affected site's server which may make remote co...

CVSS:
7.2
Affected:
up to 1.7.0
Fix:
No patched version reported
Disclosed:
Aug 27, 2024

CVE-2025-52758 on NVD →

Zippy [zippy] < 1.6.10

unknown

[en] Unrestricted Upload of File with Dangerous Type vulnerability in Gesundheit Bewegt GmbH Zippy.This issue affects Zippy: from n/a through 1.6.9.

Affected:
up to 1.6.10
Fixed in:
1.6.10
Disclosed:
Mar 21, 2024

CVE-2024-27964 on NVD →

Zippy <= 1.6.9 - Authenticated (Editor+) Arbitrary File Upload

high

The Zippy plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ZippyCore.php file in all versions up to, and including, 1.6.9. This makes it possible for authenticated attackers, with editor-level access and above, to upload arbitrary files on the affected site's serve...

CVSS:
7.2
Affected:
up to 1.6.9
Fixed in:
1.6.10
Disclosed:
Mar 13, 2024

CVE-2024-27964 on NVD →

Zippy [zippy] < 1.6.6

unknown

[en] Deserialization of Untrusted Data vulnerability in Gesundheit Bewegt GmbH Zippy.This issue affects Zippy: from n/a through 1.6.5.

Affected:
up to 1.6.6
Fixed in:
1.6.6
Disclosed:
Dec 28, 2023

CVE-2023-36381 on NVD →

Zippy [zippy] < 1.6.2

unknown

[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Gesundheit Bewegt GmbH Zippy.This issue affects Zippy: from n/a through 1.6.1.

Affected:
up to 1.6.2
Fixed in:
1.6.2
Disclosed:
Nov 30, 2023

CVE-2023-26533 on NVD →

Zippy <= 1.6.2 - Missing Authorization via adminInit

medium

The Zippy plugin for WordPress is vulnerable to unauthorized archiving and unarchiving of pages due to a missing capability check on the adminInit function in versions up to, and including, 1.6.2. This makes it possible for unauthenticated attackers to archive and unarchive pages.

CVSS:
6.5
Affected:
up to 1.6.2
Fixed in:
1.6.3
Disclosed:
Jul 12, 2023

CVE-2023-34381 on NVD →

Zippy <= 1.6.5 - Authenticated(Author+) PHP Object Injection via unzipPosts

high

The Zippy plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.6.5 via deserialization of untrusted input in the vulnerable 'unzipPosts' function. This allows authenticated attackers with author-level permissions to inject a PHP Object. No POP chain is present in the vulnerable...

CVSS:
7.5
Affected:
up to 1.6.5
Fixed in:
1.6.6
Disclosed:
Jun 28, 2023

CVE-2023-36381 on NVD →

Zippy <= 1.6.1 - Authenticated (Contributor+) Sensitive Information Disclosure

medium

The Zippy plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.6.1 via the adminInit function. This can allow authenticated attackers with access to the post editor, such as contributors, to create an export that will contain sensitive author information, such as user...

CVSS:
4.3
Affected:
up to 1.6.1
Fixed in:
1.6.2
Disclosed:
Mar 30, 2023

CVE-2023-26533 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database