CVE-2024-7856: MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar <= 5.7.0.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Deletion
The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the removeTempFiles() function and insufficient path validation on the 'file' parameter in all versions up to, and including, 5.7.0.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary files which can make remote code execution possible when wp-config.php is deleted.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7856?
CVE-2024-7856 has a high severity level due to the potential for unauthorized arbitrary file deletion.
How do I fix CVE-2024-7856?
To fix CVE-2024-7856, ensure to update the Sonaar MP3 Audio Player plugin to the latest version that addresses this vulnerability.
Which versions of the Sonaar MP3 Audio Player are affected by CVE-2024-7856?
All versions of the Sonaar MP3 Audio Player plugin for WordPress below 5.7.1 are affected by CVE-2024-7856.
What attack vectors are associated with CVE-2024-7856?
CVE-2024-7856 can be exploited remotely by an attacker to delete arbitrary files on the server without proper authorization.
Is CVE-2024-7856 currently being exploited in the wild?
As of the latest information, there is no confirmed evidence that CVE-2024-7856 is actively being exploited in the wild.