CVE-2025-3431

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Apr 8, 2025
CWE ID 73

Summary

CVE-2025-3431 is a vulnerability affecting the ZoomSounds - WordPress Wave Audio Player with Playlist plugin. In all versions up to 6.91, an Arbitrary File Read vulnerability exists. This issue allows unauthenticated attackers to read the contents of files on the server using the 'dzsap_download' action. These files may contain sensitive information, posing a significant risk to security. WordPress users are advised to update the plugin to the latest version to mitigate this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share