Executive brief
The MP3 Audio Player for Music, Radio & Podcast plugin is a WordPress component used to embed and play audio content on websites. An unauthenticated attacker can inject malicious scripts that execute in visitors' browsers, potentially stealing login credentials, session tokens, or personal data, or hijacking visitor accounts without requiring any special privileges or authentication to exploit.
Technical details
The plugin versions 5.13.1 and earlier contain a cross-site scripting (XSS) vulnerability that allows unauthenticated attackers to inject malicious JavaScript into web pages. The vulnerability requires user interaction, such as a victim clicking a crafted link or visiting a malicious page, to trigger the exploit. Upon successful exploitation, arbitrary scripts execute in the context of the vulnerable website, enabling attackers to steal sensitive data, hijack user sessions, or perform unauthorized actions. The vulnerability has been patched in version 5.14 and later.
Affected products
- Sonaar MP3 Audio Player for Music, Radio & Podcast <=5.13.1
Timeline
- 2026-09-02: disclosed
- 2026-09-01: patched: Patched in version 5.14