Extension WordPress
Vulnérabilités MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar
Cette page rassemble les failles publiées pour MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar
14 fiches
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar 4.0 – 5.10 – Unauthenticated Insecure Direct Object Reference to Sensitive Information Exposure
The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions 4.0 to 5.10 via the 'load_track_note_ajax' due to missing validation on a user…
4.0-5.10
5.11
18/02/2026
MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.11 – Unauthenticated Server-Side Request Forgery
The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.11. This makes it possible for unauthenticated attackers to…
*-5.11
5.12
15/02/2026
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar 5.3 – 5.10 – Authenticated (Author+) Server-Side Request Forgery
The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Server-Side Request Forgery in versions 5.3 to 5.10 via the 'load_lyrics_ajax_callback' function. This makes it possible for authenticated attackers,…
5.3-5.10
5.11
13/02/2026
MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.9.4 – Missing Authorization
The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 5.9.4.…
*-5.9.4
5.9.5
04/04/2025
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar <= 5.9.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via Podcast RSS Feed
The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Podcast RSS Feed in all versions up to, and including, 5.9.3 due to insufficient input…
*-5.9.3
5.9.4
30/01/2025
MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.8 – Missing Authorization
The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 5.8.…
*-5.8
5.9
30/12/2024
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar <= 5.8 – Authenticated (Contributor+) Stored Cross-Site Scripting via sonaar_audioplayer Shortcode
The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sonaar_audioplayer shortcode in all versions up to, and including, 5.8 due to insufficient…
*-5.8
5.9
18/11/2024
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar <= 5.7.0.1 – Missing Authorization to Authenticated (Subscriber+) Arbitrary File Deletion
The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the removeTempFiles() function and insufficient path validation on…
*-5.7.0.1
5.7.1
28/08/2024
MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.5 – Authenticated (Contributor+) Stored Cross-Site Scripting via sonaar_audioplayer Shortcode
The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' attribute within the plugin's sonaar_audioplayer shortcode in all versions up to, and including,…
*-5.5
5.6
09/07/2024
MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 4.10.1 – Unauthenticated Arbitrary File Download
The MP3 Audio Player for Music, Radio & Podcast by Sonaar plugin for WordPress is vulnerable to arbitrary file downloads due to insufficient file validation on the load_lyrics_ajax_callback() function in all versions up to, and including, 4.10.1. This…
*-4.10.1
5.0
05/04/2024
MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.1 – Authenticated (Contributor+) Stored Cross-Site Scripting
The MP3 Audio Player for Music, Radio & Podcast by Sonaar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.1 due to insufficient input sanitization and output escaping. This makes it…
*-5.1
5.1.1
29/03/2024
MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.1 – Missing Authorization
The MP3 Audio Player for Music, Radio & Podcast by Sonaar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 5.1. This makes…
*-5.1
5.1.1
28/03/2024
MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 4.10 – Missing Authorization to Template Import
The MP3 Audio Player for Music, Radio & Podcast by Sonaar plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the import_srmp3_template function in all versions up to, and including,…
*-4.10
4.10.1
15/11/2023
MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 2.4.1 – Multiple Admin+ Cross Site Scripting
The MP3 Audio Player for Music, Radio & Podcast by Sonaar WordPress plugin before 2.4.2 does not properly sanitize or escape data in some of its Playlist settings, allowing high privilege users to perform Cross-Site Scripting attacks
*-2.4.1
2.4.2
04/10/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.