CVE · Medium

CVE-2023-36381 — Zippy [zippy] < 1.6.6

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-36381 Zippy [zippy] < 1.6.6 Deserialization of Untrusted Data Medium 6.6 < 1.6.6 1.6.6 2023-06-28

CVE-2023-36381

The Zippy plugin through version 1.6.5 contains a PHP Object Injection vulnerability in the 'unzipPosts' function that processes untrusted serialized data, enabling authenticated users with author-level access to inject malicious objects. While the plugin itself lacks a gadget chain for exploitation, the presence of one in other installed plugins or themes could allow attackers to accomplish arbitrary file deletion, information disclosure, or remote code execution. The issue was patched in version 1.6.6.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.