CVE-2024-31343: WordPress MP3 Audio Player for Music, Radio & Podcast by Sonaar plugin <= 4.10.1 - Arbitrary File Download vulnerability
Missing Authorization vulnerability in Sonaar Music MP3 Audio Player for Music, Radio & Podcast by Sonaar.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through 4.10.1.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-31343?
CVE-2024-31343 is classified as a Missing Authorization vulnerability affecting various versions of the Sonaar MP3 Audio Player.
How do I fix CVE-2024-31343?
To fix CVE-2024-31343, update the Sonaar MP3 Audio Player for Music, Radio & Podcast to at least version 5.0 or later.
What software is affected by CVE-2024-31343?
CVE-2024-31343 affects the Sonaar MP3 Audio Player for Music, Radio & Podcast plugin in WordPress versions prior to 5.0.
What can happen if I don't address CVE-2024-31343?
If left unaddressed, CVE-2024-31343 could allow unauthorized users to access or manipulate files within the Sonaar MP3 Audio Player.
Is CVE-2024-31343 specific to any operating system?
CVE-2024-31343 is not specific to any operating system as it affects a WordPress plugin that can be used on any OS running WordPress.