Executive brief
A vulnerability exists in the Sonaar MP3 Audio Player plugin for WordPress, which is used to manage and play audio content like podcasts and music. Due to a flaw in how the plugin checks for user permissions, unauthorized individuals may be able to perform actions or modify settings that should be restricted to site administrators. While the impact is considered moderate, it could allow attackers to interfere with the plugin's functionality or site content without needing a login.
Technical details
The MP3 Audio Player for Music, Radio & Podcast by Sonaar plugin for WordPress (versions 5.12 and earlier) is vulnerable to broken access control due to missing authorization checks (CWE-862). An unauthenticated remote attacker can exploit this vulnerability to execute functions or modify data that should require higher privileges. The attack is carried out over the network without any user interaction or prior authentication. The issue is resolved in version 5.13.
Affected products
- Sonaar MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.12
Timeline
- 2026-06-10: other: Reported by researcher Ananda Dhakal
- 2026-07-22: advisory: Patchstack advisory published
- 2026-07-23: disclosed: NVD publication date