PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-104673 Sonaar CVE debrief

A Cross-site Scripting (XSS) vulnerability exists in the MP3 Audio Player for Music, Radio & Podcast by Sonaar plugin, affecting versions from n/a through 5.14.2. This issue allows for Stored XSS, potentially enabling attackers to inject malicious scripts into web pages. The vulnerability has a CVSS score of 6.5 and a severity rating of MEDIUM. Defenders should prioritize verifying the presence of this vulnerability in their inventory and assessing the potential impact on their systems. The CVE record and NVD entry provide details on the vulnerability, including its description and CVSS score.

Vendor
Sonaar
Product
MP3 Audio Player for Music, Radio & Podcast by Sonaar
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-05
Original CVE updated
2026-10-05
Advisory published
2026-10-05
Advisory updated
2026-10-05

Who should care

Defenders responsible for maintaining the security of systems using the MP3 Audio Player for Music, Radio & Podcast by Sonaar plugin should be aware of this vulnerability and take steps to verify and mitigate it.

Why it matters

This vulnerability allows for Stored XSS, potentially enabling attackers to inject malicious scripts into web pages, and defenders should prioritize verifying the presence of this vulnerability in their inventory and assessing the potential impact on their systems.

  • Potential injection of malicious scripts into web pages
  • Possible compromise of user sessions or sensitive data
  • Required verification of plugin version and vulnerability presence
  • Potential impact on the security of systems using the affected plugin

Technical summary

The MP3 Audio Player for Music, Radio & Podcast by Sonaar plugin is vulnerable to Stored Cross-site Scripting (XSS). This issue affects versions from n/a through 5.14.2. The CVSS score for this vulnerability is 6.5, with a severity rating of MEDIUM. The vulnerability allows for Stored XSS, potentially enabling attackers to inject malicious scripts into web pages. Defenders should prioritize verifying the presence of this vulnerability in their inventory and assessing the potential impact on their systems. The CVE record and NVD entry provide details on the vulnerability, including its description and CVSS score.

Defensive priority

Defenders should prioritize verifying the presence of this vulnerability in their inventory and assessing the potential impact on their systems.

Recommended defensive actions

  • Verify the presence of MP3 Audio Player for Music, Radio & Podcast by Sonaar plugin in your inventory
  • Assess the version of the plugin to determine if it is within the affected range
  • Consider implementing additional security measures to prevent XSS attacks
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, including its description and CVSS score. However, additional information on affected versions and potential exploits is limited. Defenders should verify the presence of MP3 Audio Player for Music, Radio & Podcast by Sonaar plugin in their inventory and assess the version of the plugin to determine if it is within the affected range. The vulnerability allows for Stored XSS, potentially enabling attackers to inject malicious scripts into web pages.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-104673 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-104673

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-104673 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-104673

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.