Sceawere

Vulnerability Detail

CVE-2026-16776UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Stored XSS in Sonaar MP3 Player

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.4
Creation Date
2h ago
Vendor
sonaar
Product
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 5.14.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. WordPress's save-time wp_kses_post does not neutralize the payload because the attack is delivered via shortcode attributes rather than raw HTML in post content, allowing the unescaped values to survive to render time.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.4",
  "pubDate": "2026-10-10T06:16:42.043Z",
  "pubdate": "2026-10-10T06:16:42.043Z",
  "executiveSummary": "The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress contains a Stored Cross-Site Scripting (XSS) vulnerability.\nThis vulnerability, present in all versions up to and including 5.14.2, arises from the improper handling of shortcode attributes.\nAn authenticated attacker with contributor-level privileges or higher can inject malicious JavaScript into WordPress posts or pages.\nWhen a user, such as an administrator or visitor, views a page containing the malicious shortcode, the injected script executes within the context of the user's browser session.\nThe primary risk includes unauthorized actions performed on behalf of the victim, session hijacking, credential theft, and unauthorized redirection or content modification.\nBecause the vulnerability bypasses standard WordPress save-time sanitization, it presents a significant risk to site integrity and user security.\nSuccessful exploitation requires the attacker to have at least contributor-level access to the WordPress environment.",
  "technicalDetails": "The vulnerability originates from the plugin's failure to sanitize and validate input provided to shortcode attributes during the rendering process. In the WordPress ecosystem, while raw HTML content is typically processed by wp_kses_post during the saving phase, shortcode attributes are often handled differently by plugin-specific parsing logic.\nThe Sonaar MP3 Audio Player plugin fails to implement adequate output escaping for these attributes before they are rendered to the front-end. Consequently, an attacker can supply malicious payloads—such as event handlers (e.g., onerror, onload) or script tags—within the parameters of the plugin's shortcode.\nThe attack flow begins when an authenticated attacker with contributor access creates or edits a post or page containing the malicious shortcode. Because the plugin processes these attributes during the rendering phase, the malicious payload is stored in the WordPress database within the shortcode string.\nWhen a victim visits the infected page, the plugin renders the shortcode attributes directly into the HTML response without proper neutralization. The browser then interprets these unescaped attributes as executable code rather than plain text. This allows for the execution of arbitrary JavaScript in the victim's browser, essentially bypassing the security controls that would otherwise stop direct HTML injection.\nThe impact of this Stored XSS vulnerability is severe, as it facilitates full client-side compromise. An attacker can leverage this access to steal session cookies, perform unauthorized administrative actions (such as creating new users or changing plugin settings), or redirect users to malicious domains. The vulnerability persists until the specific post or page is edited or the plugin is updated to implement strict input sanitization and output escaping mechanisms such as esc_attr() or similar WordPress security functions.\nThe vulnerability affects all versions of the Sonaar MP3 Audio Player plugin up to 5.14.2. Given that contributor-level users can create and edit their own posts, the attack surface is wide, as these users can embed the malicious shortcodes in content that other users or administrators may later view."
}
CVE-2026-16776: Stored XSS in Sonaar MP3 Player (MEDIUM Severity, CVSS: 6.4) | Sceawere