What the vulnerability does
01Description
Missing Authorization vulnerability in sonaar MP3 Audio Player for Music, Radio & Podcast by Sonaar mp3-music-player-by-sonaar allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through <= 5.8.
Explanation of Vulnerability in Simple Terms
02Summary
The MP3 Audio Player for Music, Radio & Podcast by Sonaar plugin does not properly check user permissions before allowing access to certain functions. A logged-in user with low privileges can read, modify, or delete data they should not have access to. Update to a version newer than 5.8 to fix this issue.
What an attacker can do
03Attacker Capabilities
Read, modify, or delete data without proper authorization as a low-privilege logged-in user.
Potential impact on your site
04Site Impact
Unauthorized users can access or alter plugin data, potentially exposing or corrupting audio player settings and content.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege account on the site (e.g., subscriber or contributor role).
Key dates
06Disclosure timeline
January 2, 2025
CVE published
May 11, 2026
Record updated