Impact
The vulnerability is a missing authorization flaw that allows an attacker to exploit incorrectly configured access control settings in the Sonaar MP3 Audio Player plugin. Because the plugin does not properly check user permissions, an unauthenticated or low‑privilege user could potentially modify plugin settings, upload or delete audio files, or otherwise alter the configuration, undermining the integrity of the site.
Affected Systems
The flaw affects the Sonaar MP3 Audio Player for Music, Radio & Podcast plugin for WordPress in all versions up to and including 5.9.4. WordPress sites that have installed any of these affected releases are exposed. The issue is limited to the MP3 Audio Player plugin and does not extend to core WordPress or other plugins.
Risk and Exploitability
The CVSS v3 base score of 4.3 indicates a medium‑to‑low severity, and the EPSS under 1% suggests a very low probability of exploitation at this time. The vulnerability is listed as not part of the CISA KEV catalog. An attacker would need to target the plugin’s administrative endpoints, and because the access control is flawed, even users with limited permissions could succeed. The impact is primarily to configuration integrity, with a possible indirect effect on site availability if key media becomes wrongfully altered or removed.
OpenCVE Enrichment
EUVD