Plugin Vulnerability Hub
Plugin 9 known issues Latest disclosed Jun 03, 2025

ZoomSounds - WordPress Wave Audio Player with Playlist Vulnerabilities

Review known vulnerability records for the WordPress plugin ZoomSounds - WordPress Wave Audio Player with Playlist (`dzs-zoomsounds`), including severity, CVE references, affected versions, and patch status.

Recent tracked CVEs on this page include CVE-2025-47566, CVE-2025-47568 and CVE-2025-3431, so operators can jump from disclosure to patch validation without scanning the full feed first.

Known Records
9
High or Critical
7
Patch Coverage
100%
Last Updated
Jul 09, 2025
Priority CVE Quick Links

Fast paths into ZoomSounds - WordPress Wave Audio Player with Playlist CVE reports

Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.

Indexed CVEs
9
CVE-2025-47568 Critical No patch listed
CVE-2025-47568 ZoomSounds - WordPress Wave Audio Player with Playlist Vulnerability

ZoomSounds <= 6.91 - Unauthenticated PHP Object Injection

CVE-2021-4449 Critical 6.05
CVE-2021-4449 ZoomSounds - WordPress Wave Audio Player with Playlist Remote Code Execution

ZoomSounds <= 5.96 - Unauthenticated Arbitrary File Upload

CVE-2015-9471 Critical 3.0
CVE-2015-9471 ZoomSounds - WordPress Wave Audio Player with Playlist Arbitrary File Upload

ZoomSounds <= 2.0 - Arbitrary File Upload

CVE-2024-13776 High No patch listed
CVE-2024-13776 ZoomSounds - WordPress Wave Audio Player with Playlist Vulnerability

ZoomSounds - WordPress Wave Audio Player with Playlist <= 6.91 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update and Settings Manipulation

CVE-2024-13777 High No patch listed
CVE-2024-13777 ZoomSounds - WordPress Wave Audio Player with Playlist Vulnerability

ZoomSounds - WordPress Wave Audio Player with Playlist <= 6.91 - Unauthenticated PHP Object Injection

CVE-2025-3431 High No patch listed
CVE-2025-3431 ZoomSounds - WordPress Wave Audio Player with Playlist Vulnerability

ZoomSounds - WordPress Wave Audio Player with Playlist <= 6.91 - Unauthenticated Arbitrary File Download

CVE-2021-39316 High 6.50
CVE-2021-39316 ZoomSounds - WordPress Wave Audio Player with Playlist Vulnerability

ZoomSounds - WordPress Wave Audio Player with Playlist <= 6.45 - Directory Traversal

CVE-2025-0839 Medium No patch listed
CVE-2025-0839 ZoomSounds - WordPress Wave Audio Player with Playlist Stored Cross-Site Scripting

ZoomSounds <= 6.91 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

Coverage Snapshot

What this page helps you verify fast

This hub clusters every indexed record for ZoomSounds - WordPress Wave Audio Player with Playlist so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.

Patch Visibility
9 records include a published patch path, leaving 0 with no listed safe release yet.
Severity Mix
3 critical and 4 high severity findings.
Recent CVEs
CVE-2025-47566, CVE-2025-47568 and CVE-2025-3431
Reference Workflow
Jump from the hub into the full report when you need remediation notes, exploit context, CVSS vectors, or source references.
Triage First

Open the records most likely to drive action

These recent records surface the CVE strings, patch cues, and direct report links most operators need first.

Known Vulnerabilities

Reports for ZoomSounds - WordPress Wave Audio Player with Playlist

Sorted by latest disclosure date so newly published issues surface first.

Plugin Medium Patched: No CVE-2025-47566
CVE-2025-47566: ZoomSounds <= 6.91 - Reflected Cross-Site Scripting

The ZoomSounds plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 6.91 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages tha...

Published
Jun 03, 2025
Patched Release
Not published
Affected Versions
Versions up to 6.91
Next Step
Open the full report for remediation notes and references.
Plugin Critical Patched: No CVE-2025-47568
CVE-2025-47568: ZoomSounds <= 6.91 - Unauthenticated PHP Object Injection

The ZoomSounds plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 6.91 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable so...

Published
May 20, 2025
Patched Release
Not published
Affected Versions
Versions up to 6.91
Next Step
Open the full report for remediation notes and references.
Plugin High Patched: No CVE-2025-3431
CVE-2025-3431: ZoomSounds - WordPress Wave Audio Player with Playlist <= 6.91 - Unauthenticated Arbitrary File Download

The ZoomSounds - WordPress Wave Audio Player with Playlist plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 6.91 via the 'dzsap_download' action. This makes it possible for unauthenticated attackers to read the contents of arbitrary...

Published
Apr 07, 2025
Patched Release
Not published
Affected Versions
Versions up to 6.91
Next Step
Open the full report for remediation notes and references.
Plugin High Patched: No CVE-2024-13776
CVE-2024-13776: ZoomSounds - WordPress Wave Audio Player with Playlist <= 6.91 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update and Settings Manipulation

The ZoomSounds - WordPress Wave Audio Player with Playlist plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the 'dzsap_delete_notice' AJAX action in all versions up to, and including,...

Published
Apr 04, 2025
Patched Release
Not published
Affected Versions
Versions up to 6.91
Next Step
Open the full report for remediation notes and references.
Plugin Medium Patched: No CVE-2025-0839
CVE-2025-0839: ZoomSounds <= 6.91 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The ZoomSounds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 6.91 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with c...

Published
Apr 04, 2025
Patched Release
Not published
Affected Versions
Versions up to 6.91
Next Step
Open the full report for remediation notes and references.
Plugin High Patched: No CVE-2024-13777
CVE-2024-13777: ZoomSounds - WordPress Wave Audio Player with Playlist <= 6.91 - Unauthenticated PHP Object Injection

The ZoomSounds - WordPress Wave Audio Player with Playlist plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.91 via deserialization of untrusted input from the 'margs' parameter. This makes it possible for unauthenticated attackers...

Published
Mar 04, 2025
Patched Release
Not published
Affected Versions
Versions up to 6.91
Next Step
Open the full report for remediation notes and references.
Published
Aug 30, 2021
Patched Release
6.50
Affected Versions
Versions up to 6.45
Next Step
Update to 6.50 or newer if supported.
Plugin Critical Patched: Yes CVE-2021-4449
CVE-2021-4449: ZoomSounds <= 5.96 - Unauthenticated Arbitrary File Upload

The ZoomSounds plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'savepng.php' file in versions up to, and including, 5.96. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's...

Published
Jun 24, 2021
Patched Release
6.05
Affected Versions
Versions up to 5.96
Next Step
Update to 6.05 or newer if supported.
Plugin Critical Patched: Yes CVE-2015-9471
CVE-2015-9471: ZoomSounds <= 2.0 - Arbitrary File Upload

The dzs-zoomsounds plugin through 2.0 for WordPress has admin/upload.php arbitrary file upload.

Published
Jun 01, 2015
Patched Release
3.0
Affected Versions
Versions before 3.0
Next Step
Update to 3.0 or newer if supported.