CVE-2021-39316

HIGH EXPLOITED NUCLEI

Digitalzoomstudio Zoomsounds < 6.45 - Path Traversal

Title source: rule

Description

The Zoomsounds plugin <= 6.45 for WordPress allows arbitrary files, including sensitive configuration files such as wp-config.php, to be downloaded via the `dzsap_download` action using directory traversal in the `link` parameter.

Exploits (1)

exploitdb WORKING POC
by Uriel Yochpaz · textwebappsphp
https://www.exploit-db.com/exploits/50564

Nuclei Templates (1)

WordPress DZS Zoomsounds <=6.50 - Local File Inclusion
HIGHby daffainfo

Scores

CVSS v3 7.5
EPSS 0.9353
EPSS Percentile 99.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

VulnCheck KEV 2023-11-22
CWE
CWE-22 CWE-552
Status published
Products (1)
digitalzoomstudio/zoomsounds < 6.45
Published Aug 31, 2021
Tracked Since Feb 18, 2026