Executive brief
ZoomSounds is a WordPress plugin that provides audio playback and management functionality on websites. A reflected cross-site scripting (XSS) vulnerability in versions up to 6.91 allows attackers to inject malicious scripts that execute in visitors' browsers, potentially stealing session cookies, login credentials, or hijacking user accounts. The attack requires a user to click a crafted link but does not require authentication.
Technical details
This is a reflected XSS vulnerability in ZoomSounds WordPress plugin up to version 6.91, classified as Improper Neutralization of Input During Web Page Generation (CWE-79). The vulnerability exists because user-supplied input is not properly sanitized or escaped before being rendered in web page responses. An attacker can craft a malicious URL containing JavaScript payload and trick users (via phishing or social engineering) into visiting the link; the script executes in their browser with the victim's privileges. No official patch is currently available; Patchstack has issued a mitigation rule to block exploitation attempts.
Affected products
- DZS ZoomSounds through 6.91
Timeline
- 2025-03-25: disclosed
- 2025-06-03: advisory