PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-16776 sonaar CVE debrief

The MP3 Audio Player plugin for WordPress, versions up to and including 5.14.2, is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes. This vulnerability allows authenticated attackers with contributor-level access to inject arbitrary web scripts, which will execute when a user accesses an injected page. The plugin's handling of shortcode attributes does not properly sanitize input, leading to this vulnerability. Defenders should assess exposure and prioritize verification and remediation to prevent exploitation.

Vendor
sonaar
Product
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar
CVSS
MEDIUM 6.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-10
Original CVE updated
2026-10-10
Advisory published
2026-10-10
Advisory updated
2026-10-10

Who should care

Defenders responsible for WordPress installations with the MP3 Audio Player plugin should assess exposure and prioritize verification and remediation. This includes reviewing and updating the plugin, restricting contributor-level access, and monitoring for suspicious activity. Security teams and vulnerability management teams should also be aware of this vulnerability and its potential impact on their systems.

Why it matters

The MP3 Audio Player plugin vulnerability allows authenticated attackers to inject malicious scripts, which can execute on user access, posing a risk to WordPress installations.

  • Attackers can inject malicious scripts, potentially leading to user exploitation.
  • Contributor-level access is sufficient for exploitation, increasing the attack surface.
  • Successful exploitation can lead to unauthorized script execution.

Technical summary

The MP3 Audio Player plugin for WordPress, versions up to and including 5.14.2, is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes. Authenticated attackers with contributor-level access can inject arbitrary web scripts, which will execute when a user accesses an injected page. The vulnerability arises from insufficient input sanitization and output escaping in the plugin's handling of shortcode attributes. Defenders should prioritize verifying and updating the plugin to prevent exploitation, and consider implementing compensating controls for exposed systems.

Defensive priority

Defenders should prioritize verifying and updating the MP3 Audio Player plugin to prevent exploitation.

Recommended defensive actions

  • Verify and update the MP3 Audio Player plugin to the latest version.
  • Restrict contributor-level access to prevent exploitation.
  • Monitor for suspicious activity and injected scripts.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The vulnerability exists in the MP3 Audio Player plugin's handling of shortcode attributes, allowing authenticated attackers to inject malicious scripts. The plugin does not properly sanitize input, leading to Stored Cross-Site Scripting. Defenders should verify and update the plugin to prevent exploitation. Evidence is based on CVE Program records and NVD vulnerability details.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-16776 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-16776

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-16776 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-16776

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.