Description
Unauthenticated Broken Access Control in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.12 versions.
Published: 2026-07-23
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Unauthenticated broken access control exists in MP3 Audio Player for Music, Radio & Podcast by Sonaar for WordPress plugins 5.12 and earlier. This flaw allows an attacker to reach administrative sections of the plugin that are meant for privileged users, providing the ability to change media settings or view configuration details without authentication. The vulnerability is categorized as CWE-862.

Affected Systems

WordPress installations that use the Sonaar MP3 Audio Player for Music, Radio & Podcast plugin version 5.12 or earlier are vulnerable. The issue is resolved in version 5.13 and later.

Risk and Exploitability

The CVSS score of 5.3 reflects moderate severity. The EPSS score of less than 1% indicates a low probability of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that attackers would exploit the flaw through the plugin’s web interface without needing credentials, but no public proof-of-concept is documented.

Generated by OpenCVE AI on August 4, 2026 at 15:23 UTC.

Remediation

Vendor Solution

Update the WordPress MP3 Audio Player for Music, Radio & Podcast by Sonaar Plugin to the latest available version (at least 5.13).


OpenCVE Recommended Actions

  • Upgrade the Sonaar MP3 Audio Player plugin to version 5.13 or later to eliminate the access control flaw.
  • If an immediate update is not feasible, deactivate the plugin to block unauthenticated access to privileged configuration pages.
  • Review WordPress user roles and ensure only administrators can access the plugin’s settings to enforce least privilege.

Generated by OpenCVE AI on August 4, 2026 at 15:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Sonaar
Sonaar mp3 Audio Player For Music, Radio & Podcast
Wordpress
Wordpress wordpress
Vendors & Products Sonaar
Sonaar mp3 Audio Player For Music, Radio & Podcast
Wordpress
Wordpress wordpress

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Broken Access Control in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.12 versions.
Title WordPress MP3 Audio Player for Music, Radio & Podcast by Sonaar plugin <= 5.12 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Sonaar Mp3 Audio Player For Music, Radio & Podcast
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-23T16:05:10.926Z

Reserved: 2026-07-22T08:53:52.510Z

Link: CVE-2026-65506

cve-icon Vulnrichment

Updated: 2026-07-23T16:05:07.771Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T12:18:43.887

Modified: 2026-07-23T16:17:51.820

Link: CVE-2026-65506

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T15:30:06Z

Weaknesses