Server-Side Request Forgery in Sonaar MP3 Audio Player for Music, Radio & Podcast
CVE-2026-39647
5.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 8 April 2026
What is CVE-2026-39647?
A Server-Side Request Forgery (SSRF) vulnerability in the Sonaar MP3 Audio Player for Music, Radio & Podcast plugin allows attackers to make unauthorized requests to internal services. This can lead to exposure of sensitive information and compromise of server resources. Versions from n/a to 5.11 are affected, making it crucial for users to apply patches to secure their installations against potential exploitation.
Affected Version(s)
MP3 Audio Player for Music, Radio & Podcast by Sonaar 0 <= 5.11