Unauthorized Data Modification in SoundRise Music Plugin by WordPress
CVE-2025-2103

8.8HIGH

Key Information:

Vendor
Irontemplates
Status
Soundrise Music
Vendor
CVE Published:
14 March 2025

Summary

The SoundRise Music plugin for WordPress is susceptible to unauthorized data modification, stemming from a lack of capability checks in the theironMusic_ajax() function. This vulnerability affects all versions up to and including 1.6.11. An authenticated user with subscriber-level access or higher can exploit this flaw to modify arbitrary options on the WordPress site, including the ability to change the default user role during registration to administrator. This breach allows attackers to enable user registration, granting them administrative access to compromised sites.

Affected Version(s)

SoundRise Music * <= 1.6.11

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tonn
.