← back
CVE-2021-39316

ZoomSounds <= 6.45 Unauthenticated Directory Traversal and Sensitive Information Dislosure

CVSS 7.5 HIGHEPSS 66.5%CWE-22CWE-552
The Zoomsounds plugin <= 6.45 for WordPress allows arbitrary files, including sensitive configuration files such as wp-config.php, to be downloaded via the `dzsap_download` action using directory traversal in the `link` parameter.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →