The ZoomSounds plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'savepng.php' file in versions up to, and including, 5.96. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
History

Wed, 30 Oct 2024 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Digitalzoomstudio
Digitalzoomstudio zoomsounds
CPEs cpe:2.3:a:digitalzoomstudio:zoomsounds:*:*:*:*:*:wordpress:*:*
Vendors & Products Digitalzoomstudio
Digitalzoomstudio zoomsounds

Wed, 16 Oct 2024 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Zoomit
Zoomit zoomsounds
CPEs cpe:2.3:a:zoomit:zoomsounds:*:*:*:*:*:*:*:*
Vendors & Products Zoomit
Zoomit zoomsounds
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Oct 2024 07:00:00 +0000

Type Values Removed Values Added
Description The ZoomSounds plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'savepng.php' file in versions up to, and including, 5.96. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
Title ZoomSounds <= 5.96 - Unauthenticated Arbitrary File Upload
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2024-10-16T06:43:25.290Z

Updated: 2024-10-16T19:09:26.046Z

Reserved: 2024-10-15T18:38:49.029Z

Link: CVE-2021-4449

cve-icon Vulnrichment

Updated: 2024-10-16T19:09:09.605Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-16T07:15:11.243

Modified: 2024-10-30T18:06:45.840

Link: CVE-2021-4449

cve-icon Redhat

No data.