PatchSiren cyber security CVE debrief
CVE-2026-16776 sonaar CVE debrief
The MP3 Audio Player plugin for WordPress, versions up to and including 5.14.2, is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes. This vulnerability allows authenticated attackers with contributor-level access to inject arbitrary web scripts, which will execute when a user accesses an injected page. The plugin's handling of shortcode attributes does not properly sanitize input, leading to this vulnerability. Defenders should assess exposure and prioritize verification and remediation to prevent exploitation.
- Vendor
- sonaar
- Product
- MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar
- CVSS
- MEDIUM 6.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-10
- Original CVE updated
- 2026-10-10
- Advisory published
- 2026-10-10
- Advisory updated
- 2026-10-10
Who should care
Defenders responsible for WordPress installations with the MP3 Audio Player plugin should assess exposure and prioritize verification and remediation. This includes reviewing and updating the plugin, restricting contributor-level access, and monitoring for suspicious activity. Security teams and vulnerability management teams should also be aware of this vulnerability and its potential impact on their systems.
Why it matters
The MP3 Audio Player plugin vulnerability allows authenticated attackers to inject malicious scripts, which can execute on user access, posing a risk to WordPress installations.
- Attackers can inject malicious scripts, potentially leading to user exploitation.
- Contributor-level access is sufficient for exploitation, increasing the attack surface.
- Successful exploitation can lead to unauthorized script execution.
Technical summary
The MP3 Audio Player plugin for WordPress, versions up to and including 5.14.2, is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes. Authenticated attackers with contributor-level access can inject arbitrary web scripts, which will execute when a user accesses an injected page. The vulnerability arises from insufficient input sanitization and output escaping in the plugin's handling of shortcode attributes. Defenders should prioritize verifying and updating the plugin to prevent exploitation, and consider implementing compensating controls for exposed systems.
Defensive priority
Defenders should prioritize verifying and updating the MP3 Audio Player plugin to prevent exploitation.
Recommended defensive actions
- Verify and update the MP3 Audio Player plugin to the latest version.
- Restrict contributor-level access to prevent exploitation.
- Monitor for suspicious activity and injected scripts.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The vulnerability exists in the MP3 Audio Player plugin's handling of shortcode attributes, allowing authenticated attackers to inject malicious scripts. The plugin does not properly sanitize input, leading to Stored Cross-Site Scripting. Defenders should verify and update the plugin to prevent exploitation. Evidence is based on CVE Program records and NVD vulnerability details.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-16776 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-16776
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-16776 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-16776
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
MP3 Audio Player <= 5.14.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortc
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/16xxx/CVE-2026-16776.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/mp3-music-player-by-sonaar/tags/5.13/includes/class-sonaar-music-widget.php
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/mp3-music-player-by-sonaar/tags/5.13/admin/class-sonaar-music-admin.php
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.