Extension WordPress
Vulnérabilités Zippy
Cette page rassemble les failles publiées pour Zippy, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Zippy
5 fiches
Zippy <= 1.7.0 – Authenticated (Editor+) Arbitrary File Upload
The Zippy plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 1.7.0. This makes it possible for authenticated attackers, with editor-level access and above, to…
*-1.7.0
Non indiqué
27/08/2024
Zippy <= 1.6.9 – Authenticated (Editor+) Arbitrary File Upload
The Zippy plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ZippyCore.php file in all versions up to, and including, 1.6.9. This makes it possible for authenticated attackers, with editor-level…
*-1.6.9
1.6.10
13/03/2024
Zippy <= 1.6.2 – Missing Authorization via adminInit
The Zippy plugin for WordPress is vulnerable to unauthorized archiving and unarchiving of pages due to a missing capability check on the adminInit function in versions up to, and including, 1.6.2. This makes it possible for unauthenticated attackers…
*-1.6.2
1.6.3
12/07/2023
Zippy <= 1.6.5 – Authenticated(Author+) PHP Object Injection via unzipPosts
The Zippy plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.6.5 via deserialization of untrusted input in the vulnerable 'unzipPosts' function. This allows authenticated attackers with author-level permissions to inject a…
*-1.6.5
1.6.6
28/06/2023
Zippy <= 1.6.1 – Authenticated (Contributor+) Sensitive Information Disclosure
The Zippy plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.6.1 via the adminInit function. This can allow authenticated attackers with access to the post editor, such as contributors, to create…
*-1.6.1
1.6.2
30/03/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.