Cross-site Scripting Vulnerability in Sonaar MP3 Audio Player by Sonaar
CVE-2026-104673
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 5 October 2026
What is CVE-2026-104673?
A Cross-site Scripting (XSS) vulnerability exists in the Sonaar MP3 Audio Player for Music, Radio & Podcast, allowing malicious actors to inject and execute scripts in the user's browser. This issue affects all versions of the product up to and including 5.14.2, which may put users at risk of unintended actions or data exposure. Proper input validation and output encoding are recommended to mitigate such threats.
Affected Version(s)
MP3 Audio Player for Music, Radio & Podcast by Sonaar 0 <= 5.14.2