CVE · Critical

CVE-2025-52758 — Zippy [zippy] <= 1.7.0 (unfixed)

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-52758 Zippy [zippy] <= 1.7.0 (unfixed) Unrestricted Upload of File with Dangerous Type Critical 9.1 < 1.7.0 1.7.0 2024-08-27

CVE-2025-52758

The Zippy plugin for WordPress has a security flaw that allows authorized users with elevated permissions to bypass file type restrictions when uploading files, potentially leading to unauthorized code execution on the server. This issue affects all versions of the plugin up to and including 1.7.0. The vulnerability can be exploited by attackers with sufficient access rights.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.