← WordPress Vulnerabilities
WordPress security by component

MP3 Audio Player for Music, Radio & Podcast by Sonaar

MP3 Audio Player for Music, Radio & Podcast by Sonaar is a WordPress component with 11 published CVE records in this archive. The latest tracked vulnerability was published Jul 23, 2026; the highest CVE/CNA score is 8.1.

Plugin slug: mp3-music-player-by-sonaar

CVE-2026-65506: MP3 Audio Player for Music, Radio & Podcast by Sonaar: A security weakness

MP3 Audio Player for Music, Radio & Podcast by Sonaar is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 5.12.

PublishedJul 23, 2026
Known safe version5.13
Safe version
Jul 23, 2026 CVE-2026-65506
MP3 Audio Player for Music, Radio & Podcast by Sonaar: A security weakness
MP3 Audio Player for Music, Radio & Podcast by Sonaar is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 5.12.
5.13
CVE5.3
NVDPending
Apr 08, 2026 CVE-2026-39647
MP3 Audio Player for Music, Radio & Podcast by Sonaar: Server-side request forgery
MP3 Audio Player for Music, Radio & Podcast by Sonaar is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests. The published affected range is <= 5.11.
> 5.11
CVE5.4
NVDPending
Feb 19, 2026 CVE-2026-1219
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar: A security weakness
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Apr 04, 2025 CVE-2025-32235
MP3 Audio Player for Music, Radio & Podcast by Sonaar: A security weakness
MP3 Audio Player for Music, Radio & Podcast by Sonaar is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Jan 31, 2025 CVE-2024-13157
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar: Cross-site scripting
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending
Nov 19, 2024 CVE-2024-10268
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar: Cross-site scripting
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Aug 29, 2024 CVE-2024-7856
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar: Code execution
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar is affected by code execution. Exploitation requires at least subscriber-level access. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE8.1
NVD8.1
Jul 10, 2024 CVE-2024-5664
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar: Cross-site scripting
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Apr 10, 2024 CVE-2024-31343
MP3 Audio Player for Music, Radio & Podcast by Sonaar: A security weakness
MP3 Audio Player for Music, Radio & Podcast by Sonaar is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVD7.5
Mar 31, 2024 CVE-2024-30530
MP3 Audio Player for Music, Radio & Podcast by Sonaar: Cross-site scripting
MP3 Audio Player for Music, Radio & Podcast by Sonaar is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Mar 29, 2024 CVE-2024-30487
MP3 Audio Player for Music, Radio & Podcast by Sonaar: A security weakness
MP3 Audio Player for Music, Radio & Podcast by Sonaar is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.6
NVD7.6