CVE-2023-36381
The Zippy plugin through version 1.6.5 contains a PHP Object Injection vulnerability in the 'unzipPosts' function that processes untrusted serialized data, enabling authenticated users with author-level access to inject malicious objects. While the plugin itself lacks a gadget chain for exploitation, the presence of one in other installed plugins or themes could allow attackers to accomplish arbitrary file deletion, information disclosure, or remote code execution. The issue was patched in version 1.6.6.
Based on public CVE data (MITRE/NVD).