CVE Database /
CVE-2024-30487
CVE · High
CVE-2024-30487 — MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar [mp3-music-player-by-sonaar] < 5.1.1
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-30487
|
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar [mp3-music-player-by-sonaar] < 5.1.1 |
Missing Authorization |
High
7.6
|
< 5.1.1
|
5.1.1 |
2024-03-28 |
—
|
CVE-2024-30487
The WordPress MP3 Audio Player by Sonaar plugin before version 5.1.1 contains a broken access control vulnerability that allows unauthorized users to perform actions restricted to higher-privileged accounts due to missing authorization, authentication, or nonce verification checks. Steven Julian identified and reported this flaw, which has been remedied in version 5.1.1 and later. Users should upgrade their installations immediately to address this security issue.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings