Security Research

CVE-2021-39316 DZS Zoomsounds: Unauthenticated Arbitrary File Read

#Vulnerability Analysis#Code Audit#Web Security
WordPress plugin unauthenticated arbitrary file read leaking database password

The DZS Zoomsounds plugin has a download endpoint that reads whatever path the client passes, with no permission check — crafting ../../../wp-config.php is enough to read the database password.

Unlock to view this content.