S4E just found a high-severity finding from [ai] web application login panel detection scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2015-4694 Scanner

CVE-2015-4694 scanner - Directory Traversal vulnerability in Zip Attachments plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2k
Times Used
continuous scan runs
3.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2015-4694
8.6
CVSS

Directory traversal vulnerability in download.php in the Zip Attachments plugin before 1.5.1 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the za_file parameter.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

The Zip Attachments plugin for WordPress is a tool used to simplify the process of adding downloadable files to a WordPress website. With this plugin, files can be compressed into a single ZIP file and attached to a page or post. This makes it easier for visitors to access and download the files they need.

One major vulnerability found in the plugin is identified as CVE-2015-4694. This vulnerability allows remote attackers to access arbitrary files through a directory traversal technique. Specifically, the vulnerability exists in the download.php file, which can be exploited through a '..' (dot dot) in the za_file parameter. This allows attackers to access files beyond the plugin's intended scope and potentially gain access to sensitive information.

If left unchecked, this vulnerability can lead to a wide range of consequences. Attackers can gain access to sensitive information stored in files that are otherwise hidden from public view. This can include personal information, financial information, and other sensitive data that can be used for malicious purposes. In some cases, attackers may even be able to gain full control over a website or server, further escalating the scope and severity of the attack.

Thanks to the pro features of the s4e.io platform, readers can easily and quickly learn about vulnerabilities in their digital assets. With advanced scanning capabilities and automatic alerts, the platform helps users stay on top of potential threats and take proactive measures to protect their websites and data. By partnering with s4e.io, it's possible to stay one step ahead of even the most advanced and sophisticated attacks.

 

REFERENCES

Solution Advice

To protect against this vulnerability, the following precautions can be taken:

  • Update the Zip Attachments plugin to version 1.5.1 or later, which addresses this vulnerability
  • Keep all plugins, themes, and WordPress software up to date to prevent known vulnerabilities from being exploited
  • Utilize a web application firewall (WAF) to help block attacks targeting this vulnerability
  • Disable file downloads or restrict access to files to trusted users only
  • Regularly monitor server logs and file access to identify any suspicious activity or attempts to exploit this vulnerability

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2015-4694 scanner - Directory Traversal vulnerability in Zip Attachments plugin for WordPress | S4E