Description
Server-Side Request Forgery (SSRF) vulnerability in sonaar MP3 Audio Player for Music, Radio & Podcast by Sonaar mp3-music-player-by-sonaar allows Server Side Request Forgery.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through <= 5.11.
Published: 2026-04-08
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Server‑Side Request Forgery leading to potential exposure of internal resources
Action: Patch
AI Analysis

Impact

WordPress users of the Sonaar MP3 Audio Player for Music, Radio & Podcast plugin are exposed to a Server‑Side Request Forgery flaw. The plugin accepts external URLs without adequate validation, enabling an attacker to command the vulnerable server to fetch arbitrary network locations. The result can reveal sensitive internal data, trigger actions on backend services or disrupt network services. This weakness is classified as CWE‑918 and can compromise confidentiality, integrity, or availability depending on the target services.

Affected Systems

The vulnerability affects the Sonaar MP3 Audio Player for Music, Radio & Podcast WordPress plugin, all versions up to 5.11 inclusive. All WordPress sites running a vulnerable instance of this plugin are at risk.

Risk and Exploitability

The CVSS rating is 5.4 with a low EPSS score below 1%, and the flaw is not presently listed in the CISA KEV catalog. The likely attack vector is that an attacker can submit a crafted URL to the plugin’s media input endpoint, causing the server to perform outbound HTTP requests. Attackers would need either site‑admin access or the ability to supply untrusted URLs; once the SSRF is triggered, the server could access internal hosts, potentially exposing restricted data or enabling further exploitation. The likelihood of exploitation is low, but the potential impact is serious if the server can reach sensitive infrastructure.

Generated by OpenCVE AI on April 13, 2026 at 23:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Sonaar MP3 Audio Player plugin to a version newer than 5.11.
  • If an immediate update is not possible, restrict the plugin’s ability to make outbound requests or place it behind a network firewall that blocks internal traffic.
  • Verify that the plugin does not process untrusted URLs from users or external sources.

Generated by OpenCVE AI on April 13, 2026 at 23:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Apr 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Apr 2026 08:30:00 +0000

Type Values Removed Values Added
First Time appeared Sonaar
Sonaar mp3 Audio Player For Music, Radio & Podcast
Wordpress
Wordpress wordpress
Vendors & Products Sonaar
Sonaar mp3 Audio Player For Music, Radio & Podcast
Wordpress
Wordpress wordpress

Wed, 08 Apr 2026 08:45:00 +0000

Type Values Removed Values Added
Description Server-Side Request Forgery (SSRF) vulnerability in sonaar MP3 Audio Player for Music, Radio & Podcast by Sonaar mp3-music-player-by-sonaar allows Server Side Request Forgery.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through <= 5.11.
Title WordPress MP3 Audio Player for Music, Radio & Podcast by Sonaar plugin <= 5.11 - Server Side Request Forgery (SSRF) vulnerability
Weaknesses CWE-918
References

Subscriptions

Sonaar Mp3 Audio Player For Music, Radio & Podcast
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-13T20:23:37.275Z

Reserved: 2026-04-07T10:57:48.107Z

Link: CVE-2026-39647

cve-icon Vulnrichment

Updated: 2026-04-13T20:22:17.251Z

cve-icon NVD

Status : Deferred

Published: 2026-04-08T09:16:35.620

Modified: 2026-04-24T18:06:24.707

Link: CVE-2026-39647

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-14T16:38:53Z

Weaknesses