PatchSiren

sonaar CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Sonaar CVE published 2026-06-08

CVE-2023-54351

CVE-2023-54351 is a stored cross-site scripting (XSS) vulnerability in the WordPress Sonaar Music Plugin version 4.7. The vulnerability allows unauthenticated attackers to inject malicious scripts through the comment functionality. Attackers can submit JavaScript payloads in the comment parameter to wp-comments-post.php, which are stored and executed in the browsers of users viewing the affected playlist [truncated]

MEDIUM sonaar CVE published 2026-04-08

CVE-2026-39647

A Server-Side Request Forgery (SSRF) vulnerability exists in the MP3 Audio Player for Music, Radio & Podcast by Sonaar plugin, affecting versions from n/a through 5.11. This issue allows for Server Side Request Forgery. The vulnerability has a CVSS score of 5.4 and a severity rating of MEDIUM. Users of the plugin, particularly those with versions 5.11 or earlier, should be aware of this SSRF vulnerability [truncated]