CVE · High

CVE-2024-30487 — MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar [mp3-music-player-by-sonaar] < 5.1.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-30487 MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar [mp3-music-player-by-sonaar] < 5.1.1 Missing Authorization High 7.6 < 5.1.1 5.1.1 2024-03-28

CVE-2024-30487

The WordPress MP3 Audio Player by Sonaar plugin before version 5.1.1 contains a broken access control vulnerability that allows unauthorized users to perform actions restricted to higher-privileged accounts due to missing authorization, authentication, or nonce verification checks. Steven Julian identified and reported this flaw, which has been remedied in version 5.1.1 and later. Users should upgrade their installations immediately to address this security issue.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.