CVE-2021-4457
ZoomSounds - WordPress Wave Audio Player with Playlist
Minimum safe version
6.50
Update to 6.50 or later to address 7 fixable vulnerabilities
WordPress ZoomSounds plugin <= 6.91 - Reflected Cross Site Scripting (XSS) vulnerability
WordPress ZoomSounds plugin <= 6.91 - PHP Object Injection vulnerability
ZoomSounds - WordPress Wave Audio Player with Playlist <= 6.91 - Unauthenticated Arbitrary File Download
ZoomSounds - WordPress Wave Audio Player with Playlist <= 6.91 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update and Settings Manipulation
ZoomSounds <= 6.91 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
ZoomSounds - WordPress Wave Audio Player with Playlist <= 6.91 - Unauthenticated PHP Object Injection
CVE-2021-4449
ZoomSounds < 6.05 - Unauthenticated Arbitrary File Upload
ZoomSounds <= 5.96 - Unauthenticated Arbitrary File Upload
WordPress Zoom Sounds Plugins <= 2.0 - Remote File Upload
CVE-2015-9471
CVE-2021-39316