CVE-2025-3431: ZoomSounds - WordPress Wave Audio Player with Playlist <= 6.91 - Unauthenticated Arbitrary File Download
The ZoomSounds - WordPress Wave Audio Player with Playlist plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 6.91 via the 'dzsapdownload' action. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3431?
CVE-2025-3431 is classified as a high severity vulnerability due to its potential for arbitrary file reading by unauthenticated attackers.
How do I fix CVE-2025-3431?
To fix CVE-2025-3431, update the ZoomSounds plugin to version 6.92 or later.
Who is affected by CVE-2025-3431?
CVE-2025-3431 affects all versions of the ZoomSounds - WordPress Wave Audio Player with Playlist plugin up to and including version 6.91.
What type of vulnerability is CVE-2025-3431?
CVE-2025-3431 is categorized as an Arbitrary File Read vulnerability.
Can CVE-2025-3431 be exploited remotely?
Yes, CVE-2025-3431 can be exploited remotely as it allows unauthenticated users to read arbitrary files.