ZoomSounds - WordPress Wave Audio Player with Playlist

ZoomSounds - WordPress Wave Audio Player with Playlist has 9 disclosed vulnerabilities in the WordSec catalog, reported between 2015 and 2025; 3 are fixed and 6 remain unpatched as of September 2026. Their average CVSS score is 8.1, and the most serious one scores 9.8 out of 10. Severity breakdown: 3 critical and 4 high. 2025 was the busiest year with 6 disclosures.

The most common weakness is Cross-Site Scripting, behind 2 of the records (22%). Other recurring categories include Deserialization Of Untrusted Data, Unrestricted Upload Of File With Dangerous Type.

3 of the records (33%) have a vendor fix, while 6 remain unpatched. The oldest unresolved one dates back to 2025.

7 independent researchers contributed these findings, most of them (2) reported by Lucio Sá.

Strategic Overview

Avg CVSSHigh
8.1/ 10
Patch Coverage33%
Open

6

Fixed

3

Get automatic notifications for all ZoomSounds - WordPress Wave Audio Player with Playlist vulnerabilities before they are exploited.

Most severe open issueCVSS 9.8CVE-2025-47568

ZoomSounds <= 6.91 - Unauthenticated PHP Object Injection

Read the full analysis

Vulnerability Records

9 records
2025-06-03 00:00CVE-2025-47566
6.1
Medium
Tran Nguyen Bao KhanhNo
2025-05-20 00:00CVE-2025-47568
9.8
Critical
BondsNo
2025-04-07 00:00CVE-2025-3431
7.5
High
Mohammadamin AlidoostNo
2025-04-04 16:43CVE-2024-13776
8.1
High
Lucio SáNo
2025-04-04 00:00CVE-2025-0839
6.4
Medium
István MártonNo
2025-03-04 21:11CVE-2024-13777
8.1
High
Lucio SáNo
2021-08-30 00:00CVE-2021-39316
7.5
High
DigitalJessica LtdYes
2021-06-24 00:00CVE-2021-4449
9.8
Critical
ganjYes
2015-06-01 00:00CVE-2015-9471
9.8
Critical
AnonymousYes
Showing 1–9 of 9 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C