CVE-2026-81289: WordPress MP3 Audio Player for Music, Radio & Podcast by Sonaar plugin <= 5.13.1 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.13.1 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress plugin: MP3 Audio Player for Music, Radio & Podcast by Sonaarto a version that resolves this vulnerability.Fixed in 5.14
Event History
Frequently Asked Questions
Does an attacker need a WordPress account to exploit this issue?
No. The vulnerability is unauthenticated, so it does not require attacker privileges or a WordPress account. Exploitation does require user interaction.
Which installations should be considered affected?
Installations using Sonaar WordPress MP3 Audio Player for Music, Radio & Podcast by Sonaar version 5.13.1 or earlier should be considered affected.
What is the potential impact of a successful exploit?
The provided severity vector indicates low potential impact to confidentiality, integrity, and availability, with scope changed. The issue is rated high with a CVSS score of 7.1.