CVE-2026-1219
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar 4.0 - 5.10 - Unauthenticated Insecure Direct Object Reference to Sensitive Information Exposure
CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th
The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions 4.0 to 5.10 via the 'load_track_note_ajax' due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to view the contents of private posts.
| CWE | CWE-639 |
| Vendor | sonaar |
| Product | mp3 audio player – music player, podcast player & radio by sonaar |
| Published | Feb 19, 2026 |
| Last Updated | Feb 20, 2026 |
Stay Ahead of the Next One
Get instant alerts for sonaar mp3 audio player – music player, podcast player & radio by sonaar
Be the first to know when new medium vulnerabilities affecting sonaar mp3 audio player – music player, podcast player & radio by sonaar are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
sonaar / MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar
4.0 ≤ 5.10
References
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/ce8fa964-d543-4d46-a534-e403dff4f425?source=cve plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/mp3-music-player-by-sonaar/tags/5.10/sonaar-music.php#L179 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/mp3-music-player-by-sonaar/tags/5.10/public/class-sonaar-music-public.php#L323 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset/3453076/
Credits
Kenneth Dunn