CVE-2025-32235: WordPress MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin <= 5.9.4 - Broken Access Control vulnerability
Missing Authorization vulnerability in sonaar MP3 Audio Player for Music, Radio & Podcast by Sonaar allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through 5.9.4.
Other sources
Missing Authorization vulnerability in sonaar MP3 Audio Player for Music, Radio & Podcast by Sonaar mp3-music-player-by-sonaar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through <= 5.9.4.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32235?
CVE-2025-32235 is considered a high severity vulnerability due to its impact on access control.
How do I fix CVE-2025-32235?
To fix CVE-2025-32235, update the Sonaar MP3 Audio Player for Music, Radio & Podcast to version 5.9.5 or later.
What does CVE-2025-32235 affect?
CVE-2025-32235 affects the Sonaar MP3 Audio Player for Music, Radio & Podcast versions from n/a up to 5.9.4.
What type of vulnerability is CVE-2025-32235?
CVE-2025-32235 is a missing authorization vulnerability resulting from incorrectly configured access control security levels.
Who is the vendor for CVE-2025-32235?
The vendor for CVE-2025-32235 is Sonaar, responsible for the MP3 Audio Player for Music, Radio & Podcast.