Junglewise Threat Intelligence

CVE-2025-59560: SONAAR MUSIC Sonaar XSS in WordPress theme

CVE-2025-59560 · Severity: high · CVSS 7.1 · Published 2026-06-17

Executive brief

Sonaar is a WordPress theme designed for musicians and podcasters to showcase their work. A security flaw in this theme allows unauthenticated attackers to inject malicious scripts into the website. If a site administrator or visitor interacts with a specially crafted link, the attacker could potentially steal session information, redirect users to malicious sites, or deface the website.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in the Sonaar theme for WordPress due to improper neutralization of user-supplied input during web page generation (CWE-79). The flaw allows an unauthenticated remote attacker to inject arbitrary JavaScript into the context of a user's session. Exploitation requires a victim to perform an action, such as clicking a malicious link (User Interaction: Required). Successful exploitation can lead to the execution of malicious scripts in the victim's browser, potentially allowing for session hijacking or unauthorized actions on behalf of a privileged user. The issue is resolved in version 4.27.5.

Affected products

  • SONAAR MUSIC Sonaar <= 4.27.4

Timeline

  • 2025-09-06: other: Reported by Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity)
  • 2025-10-06: disclosed: Initial disclosure by Patchstack
  • 2025-10-06: patched: Version 4.27.5 released to address the vulnerability
  • 2026-06-17: advisory: NVD publication date

References

Related threats