Impact
The vulnerability is a stored cross‑site scripting flaw in the Sonaar MP3 Audio Player plugin. User input that is not properly neutralized can be persisted by the plugin and later rendered into a webpage viewed by other visitors. This allows attacker‑controlled JavaScript to execute in the victim’s browser, potentially exposing session data or compromising the integrity of the displayed content.
Affected Systems
The affected product is the WordPress MP3 Audio Player for Music, Radio & Podcast by Sonaar plugin. All releases from the earliest available version through 5.14.2 are impacted. The plugin is deployed within WordPress sites that support plugin functionality.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate‑to‑high severity impact. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a stored XSS where an attacker submits malicious content via the plugin’s input interface. The malicious code is then served to any user who views the affected page, enabling script execution in browsers that access the site.
OpenCVE Enrichment