Input validation vulnerability in ZoomSounds – WordPress Wave Audio Player with Playlist 5.96

The ZoomSounds plugin for WordPress is vulnerable to a security issue that could allow unauthorized individuals to upload malicious files to the website. This vulnerability exists in versions of the plugin up to and including 5.96 and is caused by a lack of file type validation in the ‘savepng.php’ file. If exploited, the vulnerability could allow attackers to remotely execute code on the affected server.

Detected in:

ZoomSounds - WordPress Wave Audio Player with Playlist open vulnerable versions: >= * <= 5.96

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.