Directory Traversal Vulnerability in Zip Attachments Plugin for WordPress
CVE-2015-4694
What is CVE-2015-4694?
The Zip Attachments plugin for WordPress is susceptible to a directory traversal vulnerability, which allows remote attackers to manipulate the za_file parameter in download.php. By using specially crafted input, attackers can traverse directories and gain access to arbitrary files on the server. This can lead to the exposure of sensitive information, making it crucial for users to update to version 1.5.1 or later to mitigate this security risk. It is recommended to monitor the security of WordPress plugins regularly to prevent potential exploits.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
EPSS Score
32% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved