PT-2024-11046 · WordPress · Zoomsounds

Ganj

·

Published

2024-10-15

·

Updated

2025-11-29

·

CVE-2021-4449

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ZoomSounds plugin for WordPress versions up to and including 5.96
Description The ZoomSounds plugin for WordPress is susceptible to arbitrary file uploads because of a lack of file type validation in the savepng.php file. This allows unauthenticated attackers to upload arbitrary files to the affected site's server, potentially leading to remote code execution. The API endpoint involved is not explicitly mentioned. The vulnerable parameter is not explicitly mentioned. The vulnerable function is savepng.php.
Recommendations Update the ZoomSounds plugin to a version newer than 5.96.

Exploit

Fix

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2021-4449

Affected Products

Zoomsounds