S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Nov 21, 2025

CVE-2021-4449 Scanner

CVE-2021-4449 Scanner - Unrestricted File Upload vulnerability in ZoomSounds Plugin

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3.1k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-4449
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

The ZoomSounds plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'savepng.php' file in versions up to, and including, 5.96. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. CVE-2021-4457 is a duplicate of this.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
ZoomSounds - WordPress Wave Audio Player with Playlistby ZoomIt
0
zoomsoundsby zoomit
0
Updated Aug 21, 2026View on NVD →
Detail

ZoomSounds is a popular audio player plugin for WordPress that allows users to upload audio tracks and manage playlists on their websites. It is commonly used by bloggers, podcasters, and musicians to enhance the audio experience on their sites. The plugin offers features such as waveform visualizations, playlist management, and customizable skins, making it versatile for audio streaming purposes.

This vulnerability in the ZoomSounds Plugin allows unauthenticated users to upload arbitrary files onto a WordPress site. Unrestricted File Upload vulnerabilities can severely compromise the security of a site as they allow attackers to execute malicious scripts or store unauthorized data. This could potentially lead to the execution of harmful code or further exploitation of the website.

The technical root of this vulnerability lies in the improper handling of file uploads by the savepng.php endpoint in the ZoomSounds Plugin. The endpoint does not adequately validate or sanitize file inputs, enabling an attacker to upload potentially dangerous files. This lack of restriction allows malicious users to exploit this loophole, potentially leading to remote code execution.

Exploiting this vulnerability can have devastating effects, including the unauthorized execution of scripts, website defacement, and data breaches. Attackers may leverage this vulnerability to gain control over the affected website, plant backdoors, or launch further attacks on connected systems or networks.

REFERENCES

Solution Advice
  • Update the ZoomSounds Plugin to the latest version that addresses this vulnerability.
  • Implement server-side input validation and file sanitization to ensure only safe files are uploaded.
  • Restrict file uploads to authenticated and authorized users to mitigate the risk of exploitation.
  • Regularly monitor and audit your systems for unauthorized file uploads or changes.
  • Consider implementing additional security tools such as Web Application Firewalls (WAF) to detect and prevent malicious activities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.