BFG Tools – Extension Zipper
BFG Tools – Extension Zipper has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it is fixed as of September 2026. Their average CVSS score is 4.9, and the most serious one scores 4.9 out of 10.
The most common weakness is Path Traversal, behind 1 of the records (100%).
The one issue recorded for BFG Tools – Extension Zipper has a vendor fix available, so running the current release closes it.
All of these findings were reported by Itthidej Aramsri (Boeing777). BFG Tools – Extension Zipper is installed on roughly 10 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.
CVE-2025-13681BFG Tools – Extension Zipper <= 1.0.7 - Authenticated (Administrator+) Path Traversal via 'first_file' Parameter
Read the full analysisVulnerability Records

BFG Tools – Extension Zipper
Author
Joby Franczek
The BFG Tools – Extension Zipper lets you create on-demand ZIP files of any installed WordPress plugin directly from the admin dashboard. Perfect for backups, migrating plugins between sites, sending code to a developer, or archiving a working version before updates. All ZIP files are generated safely using PHP’s ZipArchive and saved to /wp-content/uploads/extension-zips/. Learn more or get support here: https://thebaldfatguy.com/wordpress-plugins/extension-zipper/ Features Lists every installed plugin with a “Create ZIP” button Saves ZIPs to a safe writable directory (uploads/extension-zips) Automatically names ZIPs using plugin name + version Includes a download link for the latest build Skips junk files (node_modules, .git, .DS_Store, vendor/bin, logs, etc.) Fully WP-org guideline compatible (unique prefix, safe path handling, nonces, etc.)
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C