CVE-2023-54351 is a stored cross-site scripting (XSS) vulnerability in the WordPress Sonaar Music Plugin version 4.7. The vulnerability allows unauthenticated attackers to inject malicious scripts through the comment functionality. Attackers can submit JavaScript payloads in the comment parameter to wp-comments-post.php, which are stored and executed in the browsers of users viewing the affected playlist [truncated]
A Server-Side Request Forgery (SSRF) vulnerability exists in the MP3 Audio Player for Music, Radio & Podcast by Sonaar plugin, affecting versions from n/a through 5.11. This issue allows for Server Side Request Forgery. The vulnerability has a CVSS score of 5.4 and a severity rating of MEDIUM. Users of the plugin, particularly those with versions 5.11 or earlier, should be aware of this SSRF vulnerability [truncated]