ZeroHour

CVE-2026-81289

moderate

Unauthenticated Cross-Site Scripting in MP3 Audio Player by Sonaar (WordPress)

CVSS 3.1
7.1 high
EPSS
<1%p8
Published
()
Modified
AI analysis

CVE-2026-81289 is an unauthenticated cross-site scripting (XSS) flaw in the MP3 Audio Player for Music, Radio & Podcast WordPress plugin by Sonaar, affecting all versions up to and including 5.13.1. Because the flaw requires no authentication, an unauthenticated attacker can craft a request or link that injects malicious script into pages generated through the plugin, which then executes in the browser of any user who visits or triggers the affected content. Successful exploitation allows script execution in the victim's browser context, potentially enabling actions such as session/cookie theft, redirects to attacker-controlled sites, or on-site actions performed as the victim; the CVSS scope change (S:C) indicates the impact extends beyond the vulnerable component. All WordPress sites running the plugin at version 5.13.1 or earlier are affected. There are currently no known public proofs of concept, no CISA KEV listing, and a low EPSS score (0.2% probability of exploitation within 30 days), indicating no confirmed exploitation in the wild.

What to do: Update the MP3 Audio Player by Sonaar plugin to the latest available release (any version newer than 5.13.1) as soon as possible. Until patched, review player/shortcode configurations for unsanitized user-controllable values and monitor logs for suspicious unauthenticated requests targeting the plugin. Because there is no known public exploit or in-the-wild activity, patching promptly during routine maintenance is a reasonable priority.

Affected
Sonaar MP3 Audio Player for Music, Radio & Podcast (WordPress plugin)<= 5.13.1
Estimated exposure
moderate≈20,000–30,000 WordPress sites (estimated from the plugin's reported active-install count on WordPress.org) — The plugin is distributed on WordPress.org with an active-install count in the low tens of thousands, so only a subset of those installs running version 5.13.1 or earlier is plausibly vulnerable; this is an estimate, not an exact figure.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Unauthenticated Cross Site Scripting (XSS) in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.13.1 versions.

Ecosystems
WordPress
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

In the news

No ingested article mentions this CVE yet.