CVE-2026-65506: WordPress MP3 Audio Player for Music, Radio & Podcast by Sonaar plugin <= 5.12 - Broken Access Control vulnerability
Unauthenticated Broken Access Control in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.12 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress MP3 Audio Player for Music, Radio & Podcast by Sonaar pluginto a version that resolves this vulnerability.Fixed in 5.13
Event History
Frequently Asked Questions
What is the severity of CVE-2026-65506?
The severity of CVE-2026-65506 is rated as medium with a score of 5.3.
How do I fix CVE-2026-65506?
To fix CVE-2026-65506, ensure that you update the Sonaar MP3 Audio Player plugin to version 5.13 or later.
What type of vulnerability is CVE-2026-65506?
CVE-2026-65506 is classified as an Unauthenticated Broken Access Control vulnerability.
Which versions of the Sonaar plugin are affected by CVE-2026-65506?
CVE-2026-65506 affects versions of the Sonaar MP3 Audio Player for Music, Radio & Podcast plugin up to and including version 5.12.
Is user authentication required to exploit CVE-2026-65506?
No, user authentication is not required to exploit CVE-2026-65506, making it a greater risk.