Unauthenticated Cross-Site Scripting in MP3 Audio Player by Sonaar
CVE-2026-81289

7.1HIGH

What is CVE-2026-81289?

The MP3 Audio Player for Music, Radio & Podcast by Sonaar contains a vulnerability that allows unauthenticated attackers to execute arbitrary scripts in the context of the user's browser. This can lead to data theft, session hijacking, and other malicious activities, as attackers target unsuspecting users by exploiting this flaw. It is crucial for users and administrators of this plugin to apply security updates and patches promptly to mitigate the risks associated with this vulnerability.

Affected Version(s)

MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.13.1

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

dutafi | Patchstack Bug Bounty Program
.