
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-1219 is an Insecure Direct Object Reference (IDOR) vulnerability in the MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress. It affects plugin versions 4.0 through 5.10 and allows unauthenticated attackers to view the contents of private posts by exploiting the load_track_note_ajax function, which lacks proper validation on a user-controlled key. The vulnerability was published on February 19, 2026, with a CVSS v3.1 base score of 5.3 (Medium) (Red Hat CVE).
The root cause is classified as CWE-639: Authorization Bypass Through User-Controlled Key. The load_track_note_ajax AJAX handler in the Sonaar plugin accepts a user-supplied key (post ID or similar identifier) without validating whether the requesting user has authorization to access the referenced object. Because no authentication or capability check is enforced, any unauthenticated network request supplying a valid post identifier can retrieve the content of posts marked as private in WordPress (Red Hat CVE). No special preconditions beyond network access to the WordPress site are required.
Successful exploitation allows unauthenticated remote attackers to read the contents of private WordPress posts, potentially exposing sensitive or confidential content intended only for authorized users. The impact is limited to confidentiality — there is no integrity or availability impact. Depending on the nature of the private posts (e.g., draft content, internal communications, or sensitive media metadata), data exposure could be significant for affected site owners (Red Hat CVE).
No public proof-of-concept exploit code or active in-the-wild exploitation has been reported as of the available data. The EPSS score is approximately 0.021%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The low attack complexity and lack of authentication requirements make it straightforward to exploit if a target is identified, but the limited impact scope reduces attacker incentive (Red Hat CVE).
/wp-content/plugins/mp3-music-player-by-sonaar/).wp-admin/admin-ajax.php and confirm the load_track_note_ajax action is available.?p=1, ?p=2, etc.) or by observing publicly visible post IDs on the site.wp-admin/admin-ajax.php with the action parameter set to load_track_note_ajax and a target post ID as the user-controlled key (e.g., action=load_track_note_ajax&post_id=<ID>).wp-admin/admin-ajax.php with the parameter action=load_track_note_ajax from a single or rotating IP address.admin-ajax.php with varying post ID values and no associated authenticated session cookies; HTTP 200 responses to these requests from unauthenticated sources.Users should update the Sonaar MP3 Audio Player plugin to a version beyond 5.10 that includes a fix for this vulnerability. Until a patched version is confirmed available, site administrators can mitigate risk by restricting access to wp-admin/admin-ajax.php for unauthenticated users via web server rules (e.g., nginx or Apache access controls), or by temporarily deactivating the plugin. Monitoring WordPress access logs for anomalous AJAX requests is also recommended (Red Hat CVE).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."