vendor:
Sonaar Music Plugin
by:
Furkan Karaarslan
4.1
CVSS
MEDIUM
Stored XSS
79
CWE
Product Name: Sonaar Music Plugin
Affected Version From: 4.7
Affected Version To: 4.7
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows, Linux
2023
WordPress Sonaar Music Plugin 4.7 – Stored XSS
This exploit allows an attacker to execute arbitrary JavaScript code on the target Wordpress website. By adding a malicious payload in the comment section of a published playlist, the attacker can trigger the XSS vulnerability and potentially perform actions on behalf of the user.
Mitigation:
The vendor should release an updated version of the plugin that properly sanitizes user input to prevent XSS attacks. Users are advised to update to the latest version of the plugin and sanitize user-generated content before displaying it.