WordPress Plugin Vulnerabilities
Zip Attachments < 1.5 - Arbitrary File Download
Description
The zip-attachments plugin allows arbitrary file downloads because it does not check the download path of the requested file.
Proof of Concept
Affects Plugins
References
CVE
Miscellaneous
Submitter
Larry W. Cashdollar
Submitter twitter
Verified
No
WPVDB ID
Timeline
Publicly Published
2015-06-12 (about 10 years ago)
Added
2015-06-15 (about 10 years ago)
Last Updated
2020-09-22 (about 5 years ago)