Unauthorized Data Modification in SoundRise Music Plugin by WordPress
CVE-2025-2103
What is CVE-2025-2103?
The SoundRise Music plugin for WordPress is susceptible to unauthorized data modification, stemming from a lack of capability checks in the theironMusic_ajax() function. This vulnerability affects all versions up to and including 1.6.11. An authenticated user with subscriber-level access or higher can exploit this flaw to modify arbitrary options on the WordPress site, including the ability to change the default user role during registration to administrator. This breach allows attackers to enable user registration, granting them administrative access to compromised sites.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SoundRise Music * <= 1.6.11
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved