Vulnerabilities
Summary — last 7 days
New vulnerabilities2,861▲ 226 vs. last week
Critical / high1,331▼ 99 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)237▲ 223 vs. last week
4 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Medium (5.3) | 0.29% | — | ZIP AttachmentsAI | 10/15/2025 | 10/8/2026 | The Zip Attachments plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check as well as missing post status validation in the za_create_zip_callback function in all versions up to, and including, 1.6. This makes it possible for unauthenticated attackers to download… | |
| Deferred | Medium (5.3) | 0.24% | — | ZIP AttachmentsAI | 10/15/2025 | 10/8/2026 | The Zip Attachments plugin for WordPress is vulnerable to unauthorized loss of data due to a missing authorization and capability checks on the download.php file in all versions up to, and including, 1.6. This makes it possible for unauthenticated attackers to delete arbitrary files from the current wp_upload_dir… | |
| Modified | High (7.5) | 5.3% | — | Download ZIP Attachments Project Download ZIP Attachments | 5/23/2017 | 6/17/2026 | Directory traversal vulnerability in the Download Zip Attachments plugin 1.0 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the File parameter to download.php. | |
| Modified | High (8.6) | 16% | 💥 Exploit | ZIP Attachments Project ZIP Attachments | 1/8/2016 | 6/17/2026 | Directory traversal vulnerability in download.php in the Zip Attachments plugin before 1.5.1 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the za_file parameter. |