EIP-2026-113703

PRE-CVE

WordPress Plugin dzs-zoomsounds 6.60 - Remote Code Execution (RCE) (Unauthenticated)

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-113703. PoCs published by Overthinker1877.

AI-analyzed exploit summary This exploit targets an unauthenticated RCE vulnerability in the WordPress plugin dzs-zoomsounds (version 6.60) by uploading a malicious PHP file via the savepng.php endpoint. It includes a multi-threaded scanner to identify and exploit vulnerable instances.

Description

WordPress Plugin dzs-zoomsounds 6.60 - Remote Code Execution (RCE) (Unauthenticated)

Exploits (1)

exploitdb WORKING POC
by Overthinker1877 · pythonwebappsphp
https://www.exploit-db.com/exploits/50753

This exploit targets an unauthenticated RCE vulnerability in the WordPress plugin dzs-zoomsounds (version 6.60) by uploading a malicious PHP file via the savepng.php endpoint. It includes a multi-threaded scanner to identify and exploit vulnerable instances.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: WordPress Plugin dzs-zoomsounds 6.60
No auth needed
Prerequisites: Target running WordPress with vulnerable dzs-zoomsounds plugin · Network access to the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026