CVE-2026-81289
moderateUnauthenticated Cross-Site Scripting in MP3 Audio Player by Sonaar (WordPress)
CVE-2026-81289 is an unauthenticated cross-site scripting (XSS) flaw in the MP3 Audio Player for Music, Radio & Podcast WordPress plugin by Sonaar, affecting all versions up to and including 5.13.1. Because the flaw requires no authentication, an unauthenticated attacker can craft a request or link that injects malicious script into pages generated through the plugin, which then executes in the browser of any user who visits or triggers the affected content. Successful exploitation allows script execution in the victim's browser context, potentially enabling actions such as session/cookie theft, redirects to attacker-controlled sites, or on-site actions performed as the victim; the CVSS scope change (S:C) indicates the impact extends beyond the vulnerable component. All WordPress sites running the plugin at version 5.13.1 or earlier are affected. There are currently no known public proofs of concept, no CISA KEV listing, and a low EPSS score (0.2% probability of exploitation within 30 days), indicating no confirmed exploitation in the wild.
What to do: Update the MP3 Audio Player by Sonaar plugin to the latest available release (any version newer than 5.13.1) as soon as possible. Until patched, review player/shortcode configurations for unsanitized user-controllable values and monitor logs for suspicious unauthenticated requests targeting the plugin. Because there is no known public exploit or in-the-wild activity, patching promptly during routine maintenance is a reasonable priority.
| Sonaar MP3 Audio Player for Music, Radio & Podcast (WordPress plugin) | <= 5.13.1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Unauthenticated Cross Site Scripting (XSS) in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.13.1 versions.
- Ecosystems
- WordPress
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
In the news0 stories
No ingested article mentions this CVE yet.