MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar <= 5.12 - Missing Authorization
medium
The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 5.12. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 5.12
- Fixed in:
- 5.13
- Disclosed:
- Jul 22, 2026
CVE-2026-65506 on NVD →
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar 4.0 - 5.10 - Unauthenticated Insecure Direct Object Reference to Sensitive Information Exposure
medium
The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions 4.0 to 5.10 via the 'load_track_note_ajax' due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to view the content...
- CVSS:
- 5.3
- Affected:
- 4.0 – 5.10
- Fixed in:
- 5.11
- Disclosed:
- Feb 18, 2026
CVE-2026-1219 on NVD →
MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.11 - Unauthenticated Server-Side Request Forgery
high
The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.11. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application which...
- CVSS:
- 7.2
- Affected:
- up to 5.11
- Fixed in:
- 5.12
- Disclosed:
- Feb 15, 2026
CVE-2026-39647 on NVD →
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar 5.3 - 5.10 - Authenticated (Author+) Server-Side Request Forgery
medium
The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Server-Side Request Forgery in versions 5.3 to 5.10 via the 'load_lyrics_ajax_callback' function. This makes it possible for authenticated attackers, with author level access and above, to make web requests to ar...
- CVSS:
- 5
- Affected:
- 5.3 – 5.10
- Fixed in:
- 5.11
- Disclosed:
- Feb 13, 2026
CVE-2026-1249 on NVD →
MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.9.4 - Missing Authorization
medium
The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 5.9.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perf...
- CVSS:
- 4.3
- Affected:
- up to 5.9.4
- Fixed in:
- 5.9.5
- Disclosed:
- Apr 4, 2025
CVE-2025-32235 on NVD →
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar [mp3-music-player-by-sonaar] < 5.9.5
unknown
[en] Missing Authorization vulnerability in sonaar MP3 Audio Player for Music, Radio & Podcast by Sonaar allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through 5.9.4.
- Affected:
- up to 5.9.5
- Fixed in:
- 5.9.5
- Disclosed:
- Apr 4, 2025
CVE-2025-32235 on NVD →
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar [mp3-music-player-by-sonaar] < 5.9.4
unknown
[en] The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Podcast RSS Feed in all versions up to, and including, 5.9.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for...
- Affected:
- up to 5.9.4
- Fixed in:
- 5.9.4
- Disclosed:
- Jan 31, 2025
CVE-2024-13157 on NVD →
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar <= 5.9.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Podcast RSS Feed
medium
The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Podcast RSS Feed in all versions up to, and including, 5.9.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for auth...
- CVSS:
- 6.4
- Affected:
- up to 5.9.3
- Fixed in:
- 5.9.4
- Disclosed:
- Jan 30, 2025
CVE-2024-13157 on NVD →
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar [mp3-music-player-by-sonaar] < 5.9
unknown
[en] Missing Authorization vulnerability in Sonaar Music MP3 Audio Player for Music, Radio & Podcast by Sonaar allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through 5.8.
- Affected:
- up to 5.9
- Fixed in:
- 5.9
- Disclosed:
- Jan 2, 2025
CVE-2024-56266 on NVD →
MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.8 - Missing Authorization
medium
The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 5.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perfor...
- CVSS:
- 4.3
- Affected:
- up to 5.8
- Fixed in:
- 5.9
- Disclosed:
- Dec 30, 2024
CVE-2024-56266 on NVD →
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar [mp3-music-player-by-sonaar] < 4.10.1
unknown
[en] Missing Authorization vulnerability in Sonaar Music MP3 Audio Player for Music, Radio & Podcast by Sonaar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through 4.10.
- Affected:
- up to 4.10.1
- Fixed in:
- 4.10.1
- Disclosed:
- Dec 9, 2024
CVE-2023-47822 on NVD →
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar [mp3-music-player-by-sonaar] < 5.9
unknown
[en] The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sonaar_audioplayer shortcode in all versions up to, and including, 5.8 due to insufficient input sanitization and output escaping on user supplied attributes. Thi...
- Affected:
- up to 5.9
- Fixed in:
- 5.9
- Disclosed:
- Nov 19, 2024
CVE-2024-10268 on NVD →
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar <= 5.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via sonaar_audioplayer Shortcode
medium
The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sonaar_audioplayer shortcode in all versions up to, and including, 5.8 due to insufficient input sanitization and output escaping on user supplied attributes. This mak...
- CVSS:
- 6.4
- Affected:
- up to 5.8
- Fixed in:
- 5.9
- Disclosed:
- Nov 18, 2024
CVE-2024-10268 on NVD →
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar [mp3-music-player-by-sonaar] < 5.7.1
unknown
[en] The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the removeTempFiles() function and insufficient path validation on the 'file' parameter in all versions up to, and including, 5.7.0.1...
- Affected:
- up to 5.7.1
- Fixed in:
- 5.7.1
- Disclosed:
- Aug 29, 2024
CVE-2024-7856 on NVD →
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar <= 5.7.0.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Deletion
high
The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the removeTempFiles() function and insufficient path validation on the 'file' parameter in all versions up to, and including, 5.7.0.1. Thi...
- CVSS:
- 8.1
- Affected:
- up to 5.7.0.1
- Fixed in:
- 5.7.1
- Disclosed:
- Aug 28, 2024
CVE-2024-7856 on NVD →
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar [mp3-music-player-by-sonaar] < 5.6
unknown
[en] The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' attribute within the plugin's sonaar_audioplayer shortcode in all versions up to, and including, 5.5 due to insufficient input sanitization and output escaping on use...
- Affected:
- up to 5.6
- Fixed in:
- 5.6
- Disclosed:
- Jul 10, 2024
CVE-2024-5664 on NVD →
MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via sonaar_audioplayer Shortcode
medium
The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' attribute within the plugin's sonaar_audioplayer shortcode in all versions up to, and including, 5.5 due to insufficient input sanitization and output escaping on user sup...
- CVSS:
- 6.4
- Affected:
- up to 5.5
- Fixed in:
- 5.6
- Disclosed:
- Jul 9, 2024
CVE-2024-5664 on NVD →
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar [mp3-music-player-by-sonaar] < 5.0
unknown
[en] Missing Authorization vulnerability in Sonaar Music MP3 Audio Player for Music, Radio & Podcast by Sonaar.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through 4.10.1.
- Affected:
- up to 5.0
- Fixed in:
- 5.0
- Disclosed:
- Apr 10, 2024
CVE-2024-31343 on NVD →
MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 4.10.1 - Unauthenticated Arbitrary File Download
medium
The MP3 Audio Player for Music, Radio & Podcast by Sonaar plugin for WordPress is vulnerable to arbitrary file downloads due to insufficient file validation on the load_lyrics_ajax_callback() function in all versions up to, and including, 4.10.1. This makes it possible for unauthenticated attackers to download arbitrar...
- CVSS:
- 5.3
- Affected:
- up to 4.10.1
- Fixed in:
- 5.0
- Disclosed:
- Apr 5, 2024
CVE-2024-31343 on NVD →
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar [mp3-music-player-by-sonaar] < 5.1.1
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sonaar Music MP3 Audio Player for Music, Radio & Podcast by Sonaar allows Stored XSS.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through 5.1.
- Affected:
- up to 5.1.1
- Fixed in:
- 5.1.1
- Disclosed:
- Mar 31, 2024
CVE-2024-30530 on NVD →
MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The MP3 Audio Player for Music, Radio & Podcast by Sonaar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to in...
- CVSS:
- 6.4
- Affected:
- up to 5.1
- Fixed in:
- 5.1.1
- Disclosed:
- Mar 29, 2024
CVE-2024-30530 on NVD →
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar [mp3-music-player-by-sonaar] < 5.1.1
unknown
[en] Missing Authorization vulnerability in Sonaar Music MP3 Audio Player for Music, Radio & Podcast by Sonaar.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through 5.1.
- Affected:
- up to 5.1.1
- Fixed in:
- 5.1.1
- Disclosed:
- Mar 29, 2024
CVE-2024-30487 on NVD →
MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.1 - Missing Authorization
medium
The MP3 Audio Player for Music, Radio & Podcast by Sonaar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 5.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unautho...
- CVSS:
- 4.3
- Affected:
- up to 5.1
- Fixed in:
- 5.1.1
- Disclosed:
- Mar 28, 2024
CVE-2024-30487 on NVD →
MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 4.10 - Missing Authorization to Template Import
medium
The MP3 Audio Player for Music, Radio & Podcast by Sonaar plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the import_srmp3_template function in all versions up to, and including, 4.10. This makes it possible for authenticated attackers, with subscriber-level...
- CVSS:
- 5.4
- Affected:
- up to 4.10
- Fixed in:
- 4.10.1
- Disclosed:
- Nov 15, 2023
CVE-2023-47822 on NVD →
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar [mp3-music-player-by-sonaar] < 2.4.2
unknown
[en] The MP3 Audio Player for Music, Radio & Podcast by Sonaar WordPress plugin before 2.4.2 does not properly sanitize or escape data in some of its Playlist settings, allowing high privilege users to perform Cross-Site Scripting attacks
- Affected:
- up to 2.4.2
- Fixed in:
- 2.4.2
- Disclosed:
- Nov 1, 2021
CVE-2021-24624 on NVD →
MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 2.4.1 - Multiple Admin+ Cross Site Scripting
medium
The MP3 Audio Player for Music, Radio & Podcast by Sonaar WordPress plugin before 2.4.2 does not properly sanitize or escape data in some of its Playlist settings, allowing high privilege users to perform Cross-Site Scripting attacks
- CVSS:
- 5.5
- Affected:
- up to 2.4.1
- Fixed in:
- 2.4.2
- Disclosed:
- Oct 4, 2021
CVE-2021-24624 on NVD →