CVE-2025-11692

⚪ Do wiadomości

Brak kontroli autoryzacji w wtyczce Zip Attachments dla WordPressa umożliwia nieautoryzowane usunięcie plików.

CVSS
5.3
EPSS
0.2%
Exploit
none
Vendor
Opis źródłowy (NVD)

The Zip Attachments plugin for WordPress is vulnerable to unauthorized loss of data due to a missing authorization and capability checks on the download.php file in all versions up to, and including, 1.6. This makes it possible for unauthenticated attackers to delete arbitrary files from the current wp_upload_dir directory.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS5.3
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.2%
Opublikowano (NVD)2025-10-15 09:15:42 UTC
Ostatnia modyfikacja (NVD)2026-10-08 12:10:00 UTC
Referencje