Impact
An unauthenticated Cross‑Site Scripting vulnerability exists in the WordPress MP3 Audio Player for Music, Radio & Podcast by Sonaar plugin versions 5.13.1 and earlier. The flaw allows an attacker to inject arbitrary HTML or JavaScript into pages served by the plugin, potentially leading to session hijacking, defacement, or phishing attacks against site visitors.
Affected Systems
The vulnerability affects WordPress sites that have the Sonaar MP3 Audio Player for Music, Radio & Podcast plugin installed at version 5.13.1 or older. This is the only product listed by the CNA and no additional vendor or version details are provided.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity. EPSS data is not available, and the flaw is not listed in the CISA KEV catalog, so current exploitation evidence is unknown. Attackers can exploit the XSS by sending the victim to a crafted URL or embedding malicious content within the plugin’s display parameters, requiring no authentication.
OpenCVE Enrichment