Impact
A stored cross‑site scripting flaw exists in the MP3 Audio Player plugin for WordPress caused by insufficient sanitization of shortcode attributes. An authenticated user with contributor-level or higher permissions can inject arbitrary JavaScript into the shortcode’s attributes. When the content is rendered, the malicious script executes in users’ browsers, potentially enabling credential theft, session hijacking, or defacement. The vulnerability is a classic input validation failure (CWE‑79).
Affected Systems
The MP3 Audio Player plugin by Sonaar, versions up to and including 5.14.2, is affected. Any WordPress installation running these plugin versions and granting contributor‑level access to users is at risk.
Risk and Exploitability
The CVSS base score of 6.4 indicates a moderate severity. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog. An attacker must first obtain contributor or higher permissions. Once achieved, the attacker can embed malicious script that persists in stored content and runs for all subsequent visitors, providing widespread potential impact.
OpenCVE Enrichment