WordPress Zoomsounds plugin 6.45 and earlier allows arbitrary files, including sensitive configuration files such as wp-config.php, to be downloaded via the dzsap_download action using directory traversal in the link parameter.
View the template here CVE-2021-39316.yaml
References:
https://wpscan.com/vulnerability/d2d60cf7-e4d3-42b6-8dfe-7809f87547bd