Sceawere
Vulnerability Detail
CVE-2026-104673UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Stored XSS in Sonaar MP3 Player
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 10h ago
- Vendor
- Sonaar
- Product
- MP3 Audio Player for Music, Radio & Podcast by Sonaar
- Attack Type
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sonaar MP3 Audio Player for Music, Radio & Podcast by Sonaar mp3-music-player-by-sonaar allows Stored XSS.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through 5.14.2.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-10-05T09:17:08.890Z",
"pubdate": "2026-10-05T09:17:08.890Z",
"executiveSummary": "The MP3 Audio Player for Music, Radio & Podcast by Sonaar is vulnerable to a Stored Cross-Site Scripting (XSS) vulnerability due to improper neutralization of user-supplied input during web page generation.\nThis vulnerability, affecting versions from n/a through 5.14.2, allows an unauthenticated or authenticated attacker to inject malicious JavaScript into the application's database.\nThe primary risk involves the persistent execution of arbitrary scripts in the context of a victim's browser session whenever the affected page containing the malicious payload is rendered.\nSuccessful exploitation enables an attacker to compromise user sessions, steal session cookies, capture sensitive information, or perform unauthorized actions on behalf of the victim.\nThe vulnerability highlights a failure in input sanitization or output encoding mechanisms within the plugin's data handling logic.\nUsers and administrators are advised to restrict access to input fields susceptible to script injection and monitor for plugin updates that address these sanitization gaps.",
"technicalDetails": "The identified vulnerability is categorized as Stored Cross-Site Scripting (XSS), stemming from the application's failure to adequately sanitize user input before storing it in the backend database or rendering it within the Document Object Model (DOM).\nIn the context of the MP3 Audio Player for Music, Radio & Podcast by Sonaar plugin (versions n/a through 5.14.2), the application processes user-provided content—likely through configuration fields, track metadata, or player settings—without sufficient validation or context-aware output encoding.\nThe attack flow initiates when an attacker inputs a malicious JavaScript payload into an input field processed by the plugin. Because the application does not neutralize this input, the payload is persisted directly into the server's database.\nUpon subsequent requests, the application retrieves this malicious string and embeds it directly into the HTML response delivered to any user accessing the affected page. When a victim's browser parses this response, the injected script executes within the security context of the origin site.\nThis execution environment grants the script access to sensitive DOM objects, including document.cookie for session hijacking, local storage for data exfiltration, and the ability to manipulate the page structure to perform phishing or CSRF attacks.\nThe exploitation does not require the attacker to bypass complex security controls, provided they have access to the input vectors exposed by the plugin. Since the script is stored permanently, the payload remains active until manually purged from the database or overwritten by legitimate data.\nThe lack of strict input filtering allows for various vectors, including the injection of script tags (<script>), event handlers (e.g., onload, onerror), or other obfuscated payloads that bypass basic character filtering, as the backend fails to apply robust cross-site scripting prevention techniques such as context-aware HTML entity encoding.\nPost-exploitation, the attacker maintains control over the client-side interaction, effectively turning the victim’s browser into a mechanism for further unauthorized activity, including administrative privilege escalation if the victim possesses higher-level access to the WordPress environment."
}