Vulnerabilities > Digitalzoomstudio

DATE CVE VULNERABILITY TITLE RISK
2024-10-16 CVE-2021-4449 Unrestricted Upload of File with Dangerous Type vulnerability in Digitalzoomstudio Zoomsounds
The ZoomSounds plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'savepng.php' file in versions up to, and including, 5.96.
network
low complexity
digitalzoomstudio CWE-434
critical
9.8
2019-10-10 CVE-2015-9471 Unrestricted Upload of File with Dangerous Type vulnerability in Digitalzoomstudio Zoomsounds
The dzs-zoomsounds plugin through 2.0 for WordPress has admin/upload.php arbitrary file upload.
network
low complexity
digitalzoomstudio CWE-434
critical
9.8