Unauthorized Data Modification in SoundRise Music Plugin by WordPress
CVE-2025-2103
8.8HIGH
Key Information:
- Vendor
- Irontemplates
- Status
- Soundrise Music
- Vendor
- CVE Published:
- 14 March 2025
Summary
The SoundRise Music plugin for WordPress is susceptible to unauthorized data modification, stemming from a lack of capability checks in the theironMusic_ajax() function. This vulnerability affects all versions up to and including 1.6.11. An authenticated user with subscriber-level access or higher can exploit this flaw to modify arbitrary options on the WordPress site, including the ability to change the default user role during registration to administrator. This breach allows attackers to enable user registration, granting them administrative access to compromised sites.
Affected Version(s)
SoundRise Music * <= 1.6.11
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Tonn