WordPress Plugin Vulnerabilities

Zip Attachments < 1.5 - Arbitrary File Download

Description

The zip-attachments plugin allows arbitrary file downloads because it does not check the download path of the requested file.

Proof of Concept

Affects Plugins

Fixed in 1.5

References

Miscellaneous

Submitter
Larry W. Cashdollar
Submitter twitter
Verified
No

Timeline

Publicly Published
2015-06-12 (about 10 years ago)
Added
2015-06-15 (about 10 years ago)
Last Updated
2020-09-22 (about 5 years ago)

Other