Record summary

CVE-2015-4694 has a selected CVSS score of 8.6 (high); EIP currently links 1 Nuclei template.

Description

Directory traversal vulnerability in download.php in the Zip Attachments plugin before 1.5.1 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the za_file parameter.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryHIGHWordPress Zip Attachments <= 1.1.4 - Arbitrary File RetrievalCVSS 8.6

WordPress zip-attachments plugin allows arbitrary file retrieval as it does not check the download path of the requested file.

Impact

Arbitrary file retrieval

Remediation

Update to the latest version of the WordPress Zip Attachments plugin (1.1.4) or remove the plugin if not needed.

WeaknessesCWE-22
Authors0x_Akoko
Template tagscve2015cvewp-pluginwpscanlfiwordpresszip_attachments_projectvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
CPE: cpe:2.3:a:zip_attachments_project:zip_attachments:*:*:*:*:*:wordpress:*:*
Google: inurl:"/wp-content/plugins/zip-attachments"

Source: ProjectDiscovery

References

8