Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total2
Critical0
High0
Medium2
Reset
Showing 1-2 of 2 records
Threat Entry Updated 2025-10-16

CVE-2025-11701 - Zip Attachments Plugin

The Zip Attachments plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check as well as missing post status validation in the za_create_zip_callback function in all versions up to, and including, 1.6. This makes it possible for unauthenticated attackers to download attachments from private and password-protected posts.

PLUGIN Zip Attachments

CVE-2025-11701

MEDIUM CVSS 5.3 2025-10-15
Threat Entry Updated 2025-10-16

CVE-2025-11692 - Zip Attachments Plugin

The Zip Attachments plugin for WordPress is vulnerable to unauthorized loss of data due to a missing authorization and capability checks on the download.php file in all versions up to, and including, 1.6. This makes it possible for unauthenticated attackers to delete arbitrary files from the current wp_upload_dir directory.

PLUGIN Zip Attachments

CVE-2025-11692

MEDIUM CVSS 5.3 2025-10-15
Scroll to top