Impact
Unauthenticated broken access control exists in MP3 Audio Player for Music, Radio & Podcast by Sonaar for WordPress plugins 5.12 and earlier. This flaw allows an attacker to reach administrative sections of the plugin that are meant for privileged users, providing the ability to change media settings or view configuration details without authentication. The vulnerability is categorized as CWE-862.
Affected Systems
WordPress installations that use the Sonaar MP3 Audio Player for Music, Radio & Podcast plugin version 5.12 or earlier are vulnerable. The issue is resolved in version 5.13 and later.
Risk and Exploitability
The CVSS score of 5.3 reflects moderate severity. The EPSS score of less than 1% indicates a low probability of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that attackers would exploit the flaw through the plugin’s web interface without needing credentials, but no public proof-of-concept is documented.
OpenCVE Enrichment