Missing Authorization Vulnerability Affects Sonaar's MP3 Audio Player
CVE-2024-30487

7.6HIGH

Key Information:

Vendor
WordPress
Vendor
CVE Published:
29 March 2024

Summary

The MP3 Audio Player for Music, Radio & Podcast by Sonaar is affected by a missing authorization vulnerability. This issue allows unauthorized access to certain functions, potentially enabling attackers to manipulate audio files and settings without appropriate permissions. The vulnerability covers all versions of the MP3 Audio Player up to and including 5.1, highlighting the importance of implementing robust access controls to safeguard sensitive user data and functionality.

Affected Version(s)

MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.1

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Steven Julian (Patchstack Alliance)
.