Unauthorized File Deletion in Zip Attachments Plugin for WordPress
CVE-2025-11692
5.3MEDIUM
What is CVE-2025-11692?
The Zip Attachments plugin for WordPress contains a vulnerability that allows unauthorized users to delete files from the wp_upload_dir directory. This issue arises from a lack of adequate authorization and capability checks in the download.php file, affecting all versions up to and including 1.6. As a result, unauthenticated attackers can exploit this vulnerability to manipulate data without proper permissions, posing a significant risk to website integrity.
Affected Version(s)
Zip Attachments * <= 1.6