CVE-2024-56266: WordPress MP3 Audio Player plugin <= 5.8 - Broken Access Control vulnerability
Missing Authorization vulnerability in sonaar MP3 Audio Player for Music, Radio & Podcast by Sonaar mp3-music-player-by-sonaar allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through <= 5.8.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-56266?
CVE-2024-56266 has a moderate severity level due to missing authorization checks.
How do I fix CVE-2024-56266?
To fix CVE-2024-56266, update the Sonaar MP3 Audio Player for Music, Radio & Podcast plugin to version 5.9 or later.
What functionality is affected by CVE-2024-56266?
CVE-2024-56266 allows unauthorized access to certain functionalities not properly constrained by access control lists.
Which versions of the Sonaar MP3 Audio Player are vulnerable to CVE-2024-56266?
Versions of the Sonaar MP3 Audio Player for Music, Radio & Podcast from n/a through 5.8 are affected by CVE-2024-56266.
Is CVE-2024-56266 relevant to WordPress sites?
Yes, CVE-2024-56266 affects the Sonaar MP3 Audio Player plugin used on WordPress sites.