Логотип exploitDog
bind:CVE-2025-11692
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-11692

Количество 2

Количество 2

nvd логотип

CVE-2025-11692

4 месяца назад

The Zip Attachments plugin for WordPress is vulnerable to unauthorized loss of data due to a missing authorization and capability checks on the download.php file in all versions up to, and including, 1.6. This makes it possible for unauthenticated attackers to delete arbitrary files from the current wp_upload_dir directory.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-jr2c-fv9j-f272

4 месяца назад

The Zip Attachments plugin for WordPress is vulnerable to unauthorized loss of data due to a missing authorization and capability checks on the download.php file in all versions up to, and including, 1.6. This makes it possible for unauthenticated attackers to delete arbitrary files from the current wp_upload_dir directory.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-11692

The Zip Attachments plugin for WordPress is vulnerable to unauthorized loss of data due to a missing authorization and capability checks on the download.php file in all versions up to, and including, 1.6. This makes it possible for unauthenticated attackers to delete arbitrary files from the current wp_upload_dir directory.

CVSS3: 5.3
0%
Низкий
4 месяца назад
github логотип
GHSA-jr2c-fv9j-f272

The Zip Attachments plugin for WordPress is vulnerable to unauthorized loss of data due to a missing authorization and capability checks on the download.php file in all versions up to, and including, 1.6. This makes it possible for unauthenticated attackers to delete arbitrary files from the current wp_upload_dir directory.

CVSS3: 5.3
0%
Низкий
4 месяца назад

Уязвимостей на страницу