What the vulnerability does
01Description
Missing Authorization vulnerability in Sonaar Music MP3 Audio Player for Music, Radio & Podcast by Sonaar.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through 5.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L
What the vulnerability does
Missing Authorization vulnerability in Sonaar Music MP3 Audio Player for Music, Radio & Podcast by Sonaar.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through 5.1.
Explanation of Vulnerability in Simple Terms
The MP3 Audio Player plugin for WordPress fails to properly check user permissions before allowing certain actions. A logged-in user with low privileges can modify content or settings they should not have access to, including changing audio player configuration and potentially affecting site integrity. Update to a version newer than 5.1.
What an attacker can do
A low-privilege logged-in user can modify audio player settings and content they should not have access to.
Potential impact on your site
Unauthorized users can alter your audio player configuration, potentially disrupting podcasts, radio streams, or music playback for visitors.
Conditions required to exploit
Attacker must have a low-privilege account on the WordPress site (e.g., subscriber or contributor role).
Key dates
External resources
Related vulnerabilities