Executive brief
Music Player for WooCommerce is a WordPress plugin that enables audio playback on e-commerce sites. The plugin contains an unauthenticated XSS vulnerability that allows attackers to inject malicious scripts, potentially stealing visitor data, hijacking customer accounts, or defacing store pages without requiring any special privileges.
Technical details
This is an unauthenticated cross-site scripting (XSS) vulnerability in Music Player for WooCommerce versions up to and including 1.8.9. The vulnerability stems from insufficient input sanitization or output encoding, allowing attackers to inject arbitrary JavaScript code. While the attack requires user interaction (a victim must visit a crafted page or click a malicious link), no authentication is needed. An attacker can exploit this to steal session cookies, capture sensitive data, perform actions on behalf of users, or redirect visitors to phishing pages. The vulnerability was patched in version 1.9.0.
Affected products
- Music Player for WooCommerce Music Player for WooCommerce <= 1.8.9
Timeline
- 2026-08-25: disclosed: Vulnerability reported by daroo
- 2026-08-27: advisory: CVE-2026-78283 published
- 2026-08-25: patched: Patched in version 1.9.0