CVE-2025-11692
⚪ Do wiadomości
Brak kontroli autoryzacji w wtyczce Zip Attachments dla WordPressa umożliwia nieautoryzowane usunięcie plików.
CVSS
5.3
EPSS
0.2%
Exploit
none
Vendor
Opis źródłowy (NVD)
The Zip Attachments plugin for WordPress is vulnerable to unauthorized loss of data due to a missing authorization and capability checks on the download.php file in all versions up to, and including, 1.6. This makes it possible for unauthenticated attackers to delete arbitrary files from the current wp_upload_dir directory.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 5.3 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.2% |
| Opublikowano (NVD) | 2025-10-15 09:15:42 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-08 12:10:00 UTC |