Executive brief
Sonaar is a WordPress theme designed for musicians and podcasters to showcase their work. A security flaw in this theme allows unauthenticated attackers to inject malicious scripts into the website. If a site administrator or visitor interacts with a specially crafted link, the attacker could potentially steal session information, redirect users to malicious sites, or deface the website.
Technical details
A Cross-Site Scripting (XSS) vulnerability exists in the Sonaar theme for WordPress due to improper neutralization of user-supplied input during web page generation (CWE-79). The flaw allows an unauthenticated remote attacker to inject arbitrary JavaScript into the context of a user's session. Exploitation requires a victim to perform an action, such as clicking a malicious link (User Interaction: Required). Successful exploitation can lead to the execution of malicious scripts in the victim's browser, potentially allowing for session hijacking or unauthorized actions on behalf of a privileged user. The issue is resolved in version 4.27.5.
Affected products
- SONAAR MUSIC Sonaar <= 4.27.4
Timeline
- 2025-09-06: other: Reported by Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity)
- 2025-10-06: disclosed: Initial disclosure by Patchstack
- 2025-10-06: patched: Version 4.27.5 released to address the vulnerability
- 2026-06-17: advisory: NVD publication date