CVE-2021-4449
ZoomSounds <= 5.96 - Unauthenticated Arbitrary File Upload
Record summary
CVE-2021-4449 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
The ZoomSounds plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'savepng.php' file in versions up to, and including, 5.96. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. CVE-2021-4457 is a duplicate of this.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Nov 7, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 16, 2024 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
ZoomSounds - WordPress Wave Audio Player with PlaylistBrowse ZoomIt / ZoomSounds - WordPress Wave Audio Player with PlaylistDefault status: unaffected | CVE List | Through 5.96 | affected |
zoomsoundsBrowse digitalzoomstudio / zoomsounds | VulnCheck | Version data not supplied | |
zoomsoundsBrowse zoomit / zoomsoundsDefault status: unknown | CVE List | Through 5.96 | affected |
Nuclei templates
1ProjectDiscoveryCRITICALZoomSounds Plugin - Unauthenticated Arbitrary File UploadCVSS 9.8
ZoomSounds plugin for WordPress contains a file upload vulnerability in savepng.php
Impact
Unauthenticated attackers can upload arbitrary PHP files via savepng.php without authentication or validation, achieving remote code execution and complete server compromise.
Remediation
Upgrade to ZoomSounds plugin version that addresses the file upload vulnerability.
Source: ProjectDiscovery