Unauthenticated Cross-Site Scripting in MP3 Audio Player by Sonaar
CVE-2026-81289
7.1HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 2 September 2026
What is CVE-2026-81289?
The MP3 Audio Player for Music, Radio & Podcast by Sonaar contains a vulnerability that allows unauthenticated attackers to execute arbitrary scripts in the context of the user's browser. This can lead to data theft, session hijacking, and other malicious activities, as attackers target unsuspecting users by exploiting this flaw. It is crucial for users and administrators of this plugin to apply security updates and patches promptly to mitigate the risks associated with this vulnerability.
Affected Version(s)
MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.13.1