PatchSiren

SONAAR MUSIC CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH SONAAR MUSIC CVE published 2026-06-17

CVE-2025-59563

A high-severity vulnerability, CVE-2025-59563, was found in the Sonaar theme for WordPress, affecting versions up to 4.27.4. This vulnerability allows for subscriber privilege escalation, potentially enabling attackers to gain elevated access to a WordPress site. The vulnerability was publicly disclosed on June 17, 2026, and has a CVSS score of 8.8, indicating a high severity level. Users of the Sonaar th [truncated]

HIGH SONAAR MUSIC CVE published 2026-06-17

CVE-2025-59560

CVE-2025-59560 is a high-severity Unauthenticated Cross Site Scripting (XSS) vulnerability in Sonaar theme versions <= 4.27.4. This vulnerability has a CVSS score of 7.1 and is considered HIGH severity. The vulnerability was published on June 17, 2026, and last modified on the same day. Users of the Sonaar theme should take immediate action to mitigate this vulnerability. The vulnerability allows unauthen [truncated]