BFG Tools – Extension Zipper

BFG Tools – Extension Zipper has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it is fixed as of September 2026. Their average CVSS score is 4.9, and the most serious one scores 4.9 out of 10.

The most common weakness is Path Traversal, behind 1 of the records (100%).

The one issue recorded for BFG Tools – Extension Zipper has a vendor fix available, so running the current release closes it.

All of these findings were reported by Itthidej Aramsri (Boeing777). BFG Tools – Extension Zipper is installed on roughly 10 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.

Strategic Overview

Avg CVSSMedium
4.9/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all BFG Tools – Extension Zipper vulnerabilities before they are exploited.

Highest severity on recordCVSS 4.9CVE-2025-13681

BFG Tools – Extension Zipper <= 1.0.7 - Authenticated (Administrator+) Path Traversal via 'first_file' Parameter

Read the full analysis

Vulnerability Records

1 records
BFG Tools – Extension Zipper banner
Latestv1.0.8

BFG Tools – Extension Zipper

Joby Franczek

Author

Joby Franczek

0.0(0)
0/100
Last Updated
2025-12-06 (9mo ago)
Active Installs
10+
Downloads
422
Requires WP
6.0+
Requires PHP
7.4+
Tested up to
WP 6.9.7
Created
2025-11-22 (10mo ago)

The BFG Tools – Extension Zipper lets you create on-demand ZIP files of any installed WordPress plugin directly from the admin dashboard. Perfect for backups, migrating plugins between sites, sending code to a developer, or archiving a working version before updates. All ZIP files are generated safely using PHP’s ZipArchive and saved to /wp-content/uploads/extension-zips/. Learn more or get support here: https://thebaldfatguy.com/wordpress-plugins/extension-zipper/ Features Lists every installed plugin with a “Create ZIP” button Saves ZIPs to a safe writable directory (uploads/extension-zips) Automatically names ZIPs using plugin name + version Includes a download link for the latest build Skips junk files (node_modules, .git, .DS_Store, vendor/bin, logs, etc.) Fully WP-org guideline compatible (unique prefix, safe path handling, nonces, etc.)

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C