Description
WordPress Plugin ZoomSounds-WordPress Wave Audio Player with Playlist is prone to a directory traversal vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue can allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin ZoomSounds-WordPress Wave Audio Player with Playlist version 6.45 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 6.50 or latest
References
https://packetstormsecurity.com/files/165146/WordPress-DZS-Zoomsounds-6.45-Arbitrary-File-Read.html
https://sploitus.com/exploit?id=1337DAY-ID-37099
https://www.wordfence.com/vulnerability-advisories/#CVE-2021-39316
Related Vulnerabilities
Oracle Database Server CVE-2012-3134 Vulnerability (CVE-2012-3134)
WordPress Plugin GiveWP-Donation and Fundraising Platform Cross-Site Scripting (2.4.6)
WordPress Plugin Awesome Support-WordPress HelpDesk & Support Cross-Site Scripting (6.0.6)
MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2018-13258)
Vanilla Forums Deserialization of Untrusted Data Vulnerability (CVE-2018-19499)