WordPress Sonaar Music Plugin 4.7 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts through the comment functionality. Attackers can submit JavaScript payloads in the comment parameter to wp-comments-post.php which are stored and executed in the browsers of users viewing the affected playlist pages.
Metrics
Affected Vendors & Products
References
History
Mon, 08 Jun 2026 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | WordPress Sonaar Music Plugin 4.7 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts through the comment functionality. Attackers can submit JavaScript payloads in the comment parameter to wp-comments-post.php which are stored and executed in the browsers of users viewing the affected playlist pages. | |
| Title | WordPress Sonaar Music Plugin 4.7 Stored XSS via Comments | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-08T01:55:29.282Z
Reserved: 2026-01-10T01:51:52.987Z
Link: CVE-2023-54351
No data.
Status : Received
Published: 2026-06-08T02:16:22.950
Modified: 2026-06-08T02:16:22.950
Link: CVE-2023-54351
No data.
OpenCVE Enrichment
No data.