Junglewise Threat Intelligence

CVE-2026-39647: Sonaar MP3 Audio Player SSRF in WordPress plugin

CVE-2026-39647 · Severity: medium · CVSS 5.4 · Published 2026-04-08

Technologies: Sonaar MP3 Audio Player for Music, Radio & Podcast. Vendors: Sonaar.

Executive brief

The Sonaar MP3 Audio Player plugin for WordPress, which is used to manage and play music, radio, and podcasts, contains a security flaw that allows unauthorized requests to be sent from the web server. An attacker could exploit this to probe internal network services or access sensitive information that is not normally accessible from the internet. This could lead to internal data exposure or be used as a stepping stone for further attacks on the organization's private infrastructure.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the Sonaar MP3 Audio Player for Music, Radio & Podcast plugin for WordPress (versions <= 5.11). The flaw allows unauthenticated attackers to induce the server to make requests to arbitrary domains or internal network addresses. While the attack complexity is rated as high, a successful exploit could allow an attacker to bypass perimeter security controls, perform internal port scanning, or access metadata services in cloud environments. The issue is addressed in version 5.12.

Affected products

  • Sonaar MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.11

Timeline

  • 2026-01-16: other: Vulnerability reported by researcher johska
  • 2026-02-15: advisory: Patchstack published advisory and assigned priority
  • 2026-04-08: disclosed: CVE published to NVD
  • 2026-02-15: patched: Version 5.12 released to address the vulnerability

References

Related threats