CVE · High

CVE-2024-31343 — MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar [mp3-music-player-by-sonaar] < 5.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-31343 MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar [mp3-music-player-by-sonaar] < 5.0 Missing Authorization High 7.5 < 5.0 5.0 2024-04-05

CVE-2024-31343

The MP3 Audio Player – Music Player, Podcast Player & Radio plugin by Sonaar contained an arbitrary file download vulnerability that allowed attackers to retrieve any file from an affected website, potentially exposing sensitive data such as credentials and backups. The flaw was identified by Yudistira Arya and affects all versions prior to 5.0. Site administrators should upgrade to version 5.0 or later to eliminate this risk.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.