CVE-2021-24624: MP3 Audio Player for Music, Radio & Podcast by Sonaar < 2.4.2 - Multiple Admin+ Cross Site Scripting
The MP3 Audio Player for Music, Radio & Podcast by Sonaar WordPress plugin before 2.4.2 does not properly sanitize or escape data in some of its Playlist settings, allowing high privilege users to perform Cross-Site Scripting attacks
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-24624?
CVE-2021-24624 is considered a high-severity vulnerability due to the potential for Cross-Site Scripting attacks.
How do I fix CVE-2021-24624?
To fix CVE-2021-24624, update the Sonaar MP3 Audio Player for Music, Radio & Podcast plugin to version 2.4.2 or later.
Who is affected by CVE-2021-24624?
CVE-2021-24624 affects any WordPress site using the Sonaar MP3 Audio Player for Music, Radio & Podcast plugin versions prior to 2.4.2.
What type of attack can be performed due to CVE-2021-24624?
CVE-2021-24624 allows high privilege users to perform Cross-Site Scripting (XSS) attacks.
Is there a known exploit for CVE-2021-24624?
While there is no public exploit reported for CVE-2021-24624, the vulnerability itself can lead to significant security issues if exploited.