CVE-2024-30530: WordPress MP3 Audio Player for Music, Radio & Podcast by Sonaar plugin <= 5.1 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sonaar Music MP3 Audio Player for Music, Radio & Podcast by Sonaar allows Stored XSS.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through 5.1.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-30530?
CVE-2024-30530 is a stored Cross-site Scripting (XSS) vulnerability which poses a significant risk to user data and application integrity.
How do I fix CVE-2024-30530?
To fix CVE-2024-30530, update the Sonaar MP3 Audio Player for Music, Radio & Podcast plugin to the latest version above 5.1.
Which versions are affected by CVE-2024-30530?
CVE-2024-30530 affects all versions of Sonaar MP3 Audio Player for Music, Radio & Podcast up to and including version 5.1.
What is Cross-site Scripting in relation to CVE-2024-30530?
In the context of CVE-2024-30530, Cross-site Scripting allows attackers to inject malicious scripts into web pages viewed by other users.
Can CVE-2024-30530 impact user data?
Yes, CVE-2024-30530 can lead to unauthorized access and manipulation of user data due to the nature of stored XSS vulnerabilities.