Description
The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 5.14.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. WordPress's save-time wp_kses_post does not neutralize the payload because the attack is delivered via shortcode attributes rather than raw HTML in post content, allowing the unescaped values to survive to render time.
Published: 2026-10-10
Score: 6.4 Medium
EPSS: n/a
KEV: No
Impact: Stored Cross‑Site Scripting (XSS)
Action: Apply Patch
AI Analysis

Impact

A stored cross‑site scripting flaw exists in the MP3 Audio Player plugin for WordPress caused by insufficient sanitization of shortcode attributes. An authenticated user with contributor-level or higher permissions can inject arbitrary JavaScript into the shortcode’s attributes. When the content is rendered, the malicious script executes in users’ browsers, potentially enabling credential theft, session hijacking, or defacement. The vulnerability is a classic input validation failure (CWE‑79).

Affected Systems

The MP3 Audio Player plugin by Sonaar, versions up to and including 5.14.2, is affected. Any WordPress installation running these plugin versions and granting contributor‑level access to users is at risk.

Risk and Exploitability

The CVSS base score of 6.4 indicates a moderate severity. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog. An attacker must first obtain contributor or higher permissions. Once achieved, the attacker can embed malicious script that persists in stored content and runs for all subsequent visitors, providing widespread potential impact.

Generated by OpenCVE AI on October 10, 2026 at 06:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Check for and apply any available plugin update that addresses the stored XSS vulnerability.
  • Restrict contributor or higher‑level user permissions from editing content that uses the plugin’s shortcodes until the patch is applied.
  • Audit existing pages, posts, or widgets that contain the plugin’s shortcodes and cleanse any malicious attribute values.

Generated by OpenCVE AI on October 10, 2026 at 06:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 05:45:00 +0000

Type Values Removed Values Added
Description The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 5.14.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. WordPress's save-time wp_kses_post does not neutralize the payload because the attack is delivered via shortcode attributes rather than raw HTML in post content, allowing the unescaped values to survive to render time.
Title MP3 Audio Player <= 5.14.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-10T05:30:58.432Z

Reserved: 2026-07-23T17:10:44.290Z

Link: CVE-2026-16776

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T06:16:42.043

Modified: 2026-10-10T06:16:42.043

Link: CVE-2026-16776

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T07:00:13Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')