CVE-2026-39647: WordPress MP3 Audio Player for Music, Radio & Podcast by Sonaar plugin <= 5.11 - Server Side Request Forgery (SSRF) vulnerability
Server-Side Request Forgery (SSRF) vulnerability in sonaar MP3 Audio Player for Music, Radio & Podcast by Sonaar mp3-music-player-by-sonaar allows Server Side Request Forgery.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through <= 5.11.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-39647?
CVE-2026-39647 has a medium severity rating due to its potential for Server Side Request Forgery (SSRF).
How do I fix CVE-2026-39647?
To mitigate CVE-2026-39647, update the Sonaar MP3 Audio Player for Music, Radio & Podcast plugin to version 5.12 or later.
What systems are affected by CVE-2026-39647?
CVE-2026-39647 affects the Sonaar MP3 Audio Player for Music, Radio & Podcast plugin versions 5.11 and earlier.
What kind of attack can be executed using CVE-2026-39647?
CVE-2026-39647 can be exploited to perform Server Side Request Forgery attacks, potentially allowing attackers to make unauthorized requests.
Is CVE-2026-39647 publicly known?
Yes, CVE-2026-39647 is publicly documented and has been assigned a CVE identifier.