CVE-2021-39316
ZoomSounds <= 6.45 Unauthenticated Directory Traversal and Sensitive Information Dislosure
The Zoomsounds plugin <= 6.45 for WordPress allows arbitrary files, including sensitive configuration files such as wp-config.php, to be downloaded via the `dzsap_download` action using directory traversal in the `link` parameter.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
ZoomIt · ZoomSounds - WordPress Wave Audio Player with Playlistpublic PoCs found — 2
cve_referencepacketstormsecurity.com/files/165146/WordPress-DZS-Zoomsounds-6.45-Arbitrary-File-Read.htmlunverifiedexploitdbwww.exploit-db.com/exploits/50564unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →