ZoomSounds WordPress Plugin Unauthenticated Arbitrary File Upload Vulnerability

Vulnerability

A vulnerability exists in the ZoomSounds WordPress plugin in versions prior to 6.05, allowing unauthenticated users to upload arbitrary files to any location on the web server. The issue has been confirmed in versions up to 5.96, and the vulnerable file has been removed in version 6.05.

Impact

Exploitation of this vulnerability allows for arbitrary file uploads, which could be used to upload malicious files such as web shells, potentially leading to remote code execution.

Reproduction

To reproduce this vulnerability, send a POST request to '/wp-content/plugins/dzs-zoomsounds/savepng.php' with the desired file name and payload. The uploaded file will be accessible at the specified location on the server.

Remediation

Users are advised to update the ZoomSounds WordPress plugin to version 6.05 or later.

Added: Jun 25, 2025, 3:26 PM
Updated: Jun 25, 2025, 3:26 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
8.7
remediation
7.7
relevance
0.2
threat
6.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.