Extension WordPress
Vulnérabilités Zip Attachments
Cette page rassemble les failles publiées pour Zip Attachments, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Zip Attachments
3 fiches
Zip Attachments <= 1.6 – Missing Authorization to Unauthenticated Private And Password-Protected Posts Attachment Disclosure
The Zip Attachments plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check as well as missing post status validation in the za_create_zip_callback function in all versions up to, and including, 1.6.…
*-1.6
Non indiqué
14/10/2025
Zip Attachments <= 1.6 – Missing Authorization to Limited File Deletion
The Zip Attachments plugin for WordPress is vulnerable to unauthorized loss of data due to a missing authorization and capability checks on the download.php file in all versions up to, and including, 1.6. This makes it possible for…
*-1.6
Non indiqué
14/10/2025
Zip Attachments <= 1.5 – Directory Traversal
Directory traversal vulnerability in download.php in the Zip Attachments plugin before 1.5.1 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the za_file parameter.
*-1.5
1.5.1
12/06/2015
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.