Extension WordPress

Vulnérabilités MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar

Cette page rassemble les failles publiées pour MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar, leurs plages de versions affectées et les correctifs signalés dans la base locale.

14Vulnérabilités
0Critiques
14Avec correctif
8,1CVSS maximal

Historique de sécurité

CVE et vulnérabilités de MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar

14 fiches

CVE-2026-1219 Moyenne · 5,3
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar

MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar 4.0 – 5.10 – Unauthenticated Insecure Direct Object Reference to Sensitive Information Exposure

The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions 4.0 to 5.10 via the 'load_track_note_ajax' due to missing validation on a user…

Versions affectées

4.0-5.10

Correctif

5.11

Publication

18/02/2026

CVE-2026-39647 Élevée · 7,2
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar

MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.11 – Unauthenticated Server-Side Request Forgery

The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.11. This makes it possible for unauthenticated attackers to…

Versions affectées

*-5.11

Correctif

5.12

Publication

15/02/2026

CVE-2026-1249 Moyenne · 5,0
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar

MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar 5.3 – 5.10 – Authenticated (Author+) Server-Side Request Forgery

The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Server-Side Request Forgery in versions 5.3 to 5.10 via the 'load_lyrics_ajax_callback' function. This makes it possible for authenticated attackers,…

Versions affectées

5.3-5.10

Correctif

5.11

Publication

13/02/2026

CVE-2025-32235 Moyenne · 4,3
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar

MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.9.4 – Missing Authorization

The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 5.9.4.…

Versions affectées

*-5.9.4

Correctif

5.9.5

Publication

04/04/2025

CVE-2024-13157 Moyenne · 6,4
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar

MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar <= 5.9.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via Podcast RSS Feed

The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Podcast RSS Feed in all versions up to, and including, 5.9.3 due to insufficient input…

Versions affectées

*-5.9.3

Correctif

5.9.4

Publication

30/01/2025

CVE-2024-10268 Moyenne · 6,4
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar

MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar <= 5.8 – Authenticated (Contributor+) Stored Cross-Site Scripting via sonaar_audioplayer Shortcode

The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sonaar_audioplayer shortcode in all versions up to, and including, 5.8 due to insufficient…

Versions affectées

*-5.8

Correctif

5.9

Publication

18/11/2024

CVE-2024-7856 Élevée · 8,1
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar

MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar <= 5.7.0.1 – Missing Authorization to Authenticated (Subscriber+) Arbitrary File Deletion

The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the removeTempFiles() function and insufficient path validation on…

Versions affectées

*-5.7.0.1

Correctif

5.7.1

Publication

28/08/2024

CVE-2024-5664 Moyenne · 6,4
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar

MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.5 – Authenticated (Contributor+) Stored Cross-Site Scripting via sonaar_audioplayer Shortcode

The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' attribute within the plugin's sonaar_audioplayer shortcode in all versions up to, and including,…

Versions affectées

*-5.5

Correctif

5.6

Publication

09/07/2024

CVE-2024-31343 Moyenne · 5,3
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar

MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 4.10.1 – Unauthenticated Arbitrary File Download

The MP3 Audio Player for Music, Radio & Podcast by Sonaar plugin for WordPress is vulnerable to arbitrary file downloads due to insufficient file validation on the load_lyrics_ajax_callback() function in all versions up to, and including, 4.10.1. This…

Versions affectées

*-4.10.1

Correctif

5.0

Publication

05/04/2024

CVE-2024-30530 Moyenne · 6,4
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar

MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.1 – Authenticated (Contributor+) Stored Cross-Site Scripting

The MP3 Audio Player for Music, Radio & Podcast by Sonaar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.1 due to insufficient input sanitization and output escaping. This makes it…

Versions affectées

*-5.1

Correctif

5.1.1

Publication

29/03/2024

CVE-2023-47822 Moyenne · 5,4
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar

MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 4.10 – Missing Authorization to Template Import

The MP3 Audio Player for Music, Radio & Podcast by Sonaar plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the import_srmp3_template function in all versions up to, and including,…

Versions affectées

*-4.10

Correctif

4.10.1

Publication

15/11/2023

CVE-2021-24624 Moyenne · 5,5
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar

MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 2.4.1 – Multiple Admin+ Cross Site Scripting

The MP3 Audio Player for Music, Radio & Podcast by Sonaar WordPress plugin before 2.4.2 does not properly sanitize or escape data in some of its Playlist settings, allowing high privilege users to perform Cross-Site Scripting attacks

Versions affectées

*-2.4.1

Correctif

2.4.2

Publication

04/10/2021

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités