The dzs-zoomsounds plugin through 2.0 for WordPress has admin/upload.php arbitrary file upload.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://wpvulndb.com/vulnerabilities/8019 | third party advisory |
https://wordpress.org/plugins/dzs-zoomsounds/#developers | not applicable |
https://packetstormsecurity.com/files/132124/ | vdb entry third party advisory |