Filtered by vendor Digitalzoomstudio Subscriptions
Filtered by product Zoomsounds Subscriptions
Total 2 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2021-39316 1 Digitalzoomstudio 1 Zoomsounds 2024-09-17 7.5 High
The Zoomsounds plugin <= 6.45 for WordPress allows arbitrary files, including sensitive configuration files such as wp-config.php, to be downloaded via the `dzsap_download` action using directory traversal in the `link` parameter.
CVE-2015-9471 1 Digitalzoomstudio 1 Zoomsounds 2024-08-06 9.8 Critical
The dzs-zoomsounds plugin through 2.0 for WordPress has admin/upload.php arbitrary file upload.