plugin

Mp3 Music Player By Sonaar Vulnerabilities

26 known security issues reported for the Mp3 Music Player By Sonaar WordPress plugin. Most recent disclosed Jul 22, 2026.

2 high 13 medium

Running Mp3 Music Player By Sonaar on your site? Check whether your installed version is affected.

Scan your site free

MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar <= 5.12 - Missing Authorization

medium

The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 5.12. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 5.12
Fixed in:
5.13
Disclosed:
Jul 22, 2026

CVE-2026-65506 on NVD →

MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar 4.0 - 5.10 - Unauthenticated Insecure Direct Object Reference to Sensitive Information Exposure

medium

The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions 4.0 to 5.10 via the 'load_track_note_ajax' due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to view the content...

CVSS:
5.3
Affected:
4.0 – 5.10
Fixed in:
5.11
Disclosed:
Feb 18, 2026

CVE-2026-1219 on NVD →

MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.11 - Unauthenticated Server-Side Request Forgery

high

The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.11. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application which...

CVSS:
7.2
Affected:
up to 5.11
Fixed in:
5.12
Disclosed:
Feb 15, 2026

CVE-2026-39647 on NVD →

MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar 5.3 - 5.10 - Authenticated (Author+) Server-Side Request Forgery

medium

The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Server-Side Request Forgery in versions 5.3 to 5.10 via the 'load_lyrics_ajax_callback' function. This makes it possible for authenticated attackers, with author level access and above, to make web requests to ar...

CVSS:
5
Affected:
5.3 – 5.10
Fixed in:
5.11
Disclosed:
Feb 13, 2026

CVE-2026-1249 on NVD →

MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.9.4 - Missing Authorization

medium

The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 5.9.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perf...

CVSS:
4.3
Affected:
up to 5.9.4
Fixed in:
5.9.5
Disclosed:
Apr 4, 2025

CVE-2025-32235 on NVD →

MP3 Audio Player – Music Player, Podcast Player &amp; Radio by Sonaar [mp3-music-player-by-sonaar] < 5.9.5

unknown

[en] Missing Authorization vulnerability in sonaar MP3 Audio Player for Music, Radio & Podcast by Sonaar allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through 5.9.4.

Affected:
up to 5.9.5
Fixed in:
5.9.5
Disclosed:
Apr 4, 2025

CVE-2025-32235 on NVD →

MP3 Audio Player – Music Player, Podcast Player &amp; Radio by Sonaar [mp3-music-player-by-sonaar] < 5.9.4

unknown

[en] The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Podcast RSS Feed in all versions up to, and including, 5.9.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for...

Affected:
up to 5.9.4
Fixed in:
5.9.4
Disclosed:
Jan 31, 2025

CVE-2024-13157 on NVD →

MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar <= 5.9.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Podcast RSS Feed

medium

The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Podcast RSS Feed in all versions up to, and including, 5.9.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for auth...

CVSS:
6.4
Affected:
up to 5.9.3
Fixed in:
5.9.4
Disclosed:
Jan 30, 2025

CVE-2024-13157 on NVD →

MP3 Audio Player – Music Player, Podcast Player &amp; Radio by Sonaar [mp3-music-player-by-sonaar] < 5.9

unknown

[en] Missing Authorization vulnerability in Sonaar Music MP3 Audio Player for Music, Radio & Podcast by Sonaar allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through 5.8.

Affected:
up to 5.9
Fixed in:
5.9
Disclosed:
Jan 2, 2025

CVE-2024-56266 on NVD →

MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.8 - Missing Authorization

medium

The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 5.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perfor...

CVSS:
4.3
Affected:
up to 5.8
Fixed in:
5.9
Disclosed:
Dec 30, 2024

CVE-2024-56266 on NVD →

MP3 Audio Player – Music Player, Podcast Player &amp; Radio by Sonaar [mp3-music-player-by-sonaar] < 4.10.1

unknown

[en] Missing Authorization vulnerability in Sonaar Music MP3 Audio Player for Music, Radio & Podcast by Sonaar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through 4.10.

Affected:
up to 4.10.1
Fixed in:
4.10.1
Disclosed:
Dec 9, 2024

CVE-2023-47822 on NVD →

MP3 Audio Player – Music Player, Podcast Player &amp; Radio by Sonaar [mp3-music-player-by-sonaar] < 5.9

unknown

[en] The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sonaar_audioplayer shortcode in all versions up to, and including, 5.8 due to insufficient input sanitization and output escaping on user supplied attributes. Thi...

Affected:
up to 5.9
Fixed in:
5.9
Disclosed:
Nov 19, 2024

CVE-2024-10268 on NVD →

MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar <= 5.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via sonaar_audioplayer Shortcode

medium

The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sonaar_audioplayer shortcode in all versions up to, and including, 5.8 due to insufficient input sanitization and output escaping on user supplied attributes. This mak...

CVSS:
6.4
Affected:
up to 5.8
Fixed in:
5.9
Disclosed:
Nov 18, 2024

CVE-2024-10268 on NVD →

MP3 Audio Player – Music Player, Podcast Player &amp; Radio by Sonaar [mp3-music-player-by-sonaar] < 5.7.1

unknown

[en] The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the removeTempFiles() function and insufficient path validation on the 'file' parameter in all versions up to, and including, 5.7.0.1...

Affected:
up to 5.7.1
Fixed in:
5.7.1
Disclosed:
Aug 29, 2024

CVE-2024-7856 on NVD →

MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar <= 5.7.0.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Deletion

high

The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the removeTempFiles() function and insufficient path validation on the 'file' parameter in all versions up to, and including, 5.7.0.1. Thi...

CVSS:
8.1
Affected:
up to 5.7.0.1
Fixed in:
5.7.1
Disclosed:
Aug 28, 2024

CVE-2024-7856 on NVD →

MP3 Audio Player – Music Player, Podcast Player &amp; Radio by Sonaar [mp3-music-player-by-sonaar] < 5.6

unknown

[en] The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' attribute within the plugin's sonaar_audioplayer shortcode in all versions up to, and including, 5.5 due to insufficient input sanitization and output escaping on use...

Affected:
up to 5.6
Fixed in:
5.6
Disclosed:
Jul 10, 2024

CVE-2024-5664 on NVD →

MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via sonaar_audioplayer Shortcode

medium

The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' attribute within the plugin's sonaar_audioplayer shortcode in all versions up to, and including, 5.5 due to insufficient input sanitization and output escaping on user sup...

CVSS:
6.4
Affected:
up to 5.5
Fixed in:
5.6
Disclosed:
Jul 9, 2024

CVE-2024-5664 on NVD →

MP3 Audio Player – Music Player, Podcast Player &amp; Radio by Sonaar [mp3-music-player-by-sonaar] < 5.0

unknown

[en] Missing Authorization vulnerability in Sonaar Music MP3 Audio Player for Music, Radio & Podcast by Sonaar.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through 4.10.1.

Affected:
up to 5.0
Fixed in:
5.0
Disclosed:
Apr 10, 2024

CVE-2024-31343 on NVD →

MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 4.10.1 - Unauthenticated Arbitrary File Download

medium

The MP3 Audio Player for Music, Radio & Podcast by Sonaar plugin for WordPress is vulnerable to arbitrary file downloads due to insufficient file validation on the load_lyrics_ajax_callback() function in all versions up to, and including, 4.10.1. This makes it possible for unauthenticated attackers to download arbitrar...

CVSS:
5.3
Affected:
up to 4.10.1
Fixed in:
5.0
Disclosed:
Apr 5, 2024

CVE-2024-31343 on NVD →

MP3 Audio Player – Music Player, Podcast Player &amp; Radio by Sonaar [mp3-music-player-by-sonaar] < 5.1.1

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sonaar Music MP3 Audio Player for Music, Radio & Podcast by Sonaar allows Stored XSS.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through 5.1.

Affected:
up to 5.1.1
Fixed in:
5.1.1
Disclosed:
Mar 31, 2024

CVE-2024-30530 on NVD →

MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The MP3 Audio Player for Music, Radio & Podcast by Sonaar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to in...

CVSS:
6.4
Affected:
up to 5.1
Fixed in:
5.1.1
Disclosed:
Mar 29, 2024

CVE-2024-30530 on NVD →

MP3 Audio Player – Music Player, Podcast Player &amp; Radio by Sonaar [mp3-music-player-by-sonaar] < 5.1.1

unknown

[en] Missing Authorization vulnerability in Sonaar Music MP3 Audio Player for Music, Radio & Podcast by Sonaar.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through 5.1.

Affected:
up to 5.1.1
Fixed in:
5.1.1
Disclosed:
Mar 29, 2024

CVE-2024-30487 on NVD →

MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.1 - Missing Authorization

medium

The MP3 Audio Player for Music, Radio & Podcast by Sonaar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 5.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unautho...

CVSS:
4.3
Affected:
up to 5.1
Fixed in:
5.1.1
Disclosed:
Mar 28, 2024

CVE-2024-30487 on NVD →

MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 4.10 - Missing Authorization to Template Import

medium

The MP3 Audio Player for Music, Radio & Podcast by Sonaar plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the import_srmp3_template function in all versions up to, and including, 4.10. This makes it possible for authenticated attackers, with subscriber-level...

CVSS:
5.4
Affected:
up to 4.10
Fixed in:
4.10.1
Disclosed:
Nov 15, 2023

CVE-2023-47822 on NVD →

MP3 Audio Player – Music Player, Podcast Player &amp; Radio by Sonaar [mp3-music-player-by-sonaar] < 2.4.2

unknown

[en] The MP3 Audio Player for Music, Radio & Podcast by Sonaar WordPress plugin before 2.4.2 does not properly sanitize or escape data in some of its Playlist settings, allowing high privilege users to perform Cross-Site Scripting attacks

Affected:
up to 2.4.2
Fixed in:
2.4.2
Disclosed:
Nov 1, 2021

CVE-2021-24624 on NVD →

MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 2.4.1 - Multiple Admin+ Cross Site Scripting

medium

The MP3 Audio Player for Music, Radio & Podcast by Sonaar WordPress plugin before 2.4.2 does not properly sanitize or escape data in some of its Playlist settings, allowing high privilege users to perform Cross-Site Scripting attacks

CVSS:
5.5
Affected:
up to 2.4.1
Fixed in:
2.4.2
Disclosed:
Oct 4, 2021

CVE-2021-24624 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database