
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar Security & Risk Analysis
wordpress.org/plugins/mp3-music-player-by-sonaarThe most advanced Audio Player for Music & Podcast. For Elementor, Gutenberg, WooCommerce and more. Add unlimited players to any pages!
Is MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar Safe to Use in 2026?
Generally Safe
Score 92/100MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar has a strong security track record. Known vulnerabilities have been patched promptly.
The "mp3-music-player-by-sonaar" plugin exhibits a mixed security posture. While it demonstrates good practices in SQL query handling with 100% prepared statements and a high rate of output escaping (81%), several areas raise concerns. The presence of 24 AJAX handlers, with one lacking authentication checks, presents a significant attack surface that could be exploited by unauthenticated users. Taint analysis identified one flow with unsanitized paths, which, although not classified as critical or high severity in this instance, indicates a potential for data handling vulnerabilities. The plugin's historical vulnerability record is concerning, with a total of 13 known CVEs, including one high and twelve medium severity issues, with common types being Authorization Bypass, SSRF, XSS, and Missing Authorization. The last vulnerability being in 2026 suggests potential for newly discovered issues or that the listed CVEs may not fully reflect the current state of the codebase. Overall, the plugin has some strong security foundations but requires attention to its AJAX endpoint security and historical vulnerability patterns.
Key Concerns
- Unprotected AJAX handler
- Flow with unsanitized paths
- Bundled outdated library (Select2 v3.0.3)
- High number of historical medium/high CVEs
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar Security Vulnerabilities
CVEs by Year
Severity Breakdown
13 total CVEs
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar 4.0 - 5.10 - Unauthenticated Insecure Direct Object Reference to Sensitive Information Exposure
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar 5.3 - 5.10 - Authenticated (Author+) Server-Side Request Forgery
MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.9.4 - Missing Authorization
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar <= 5.9.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Podcast RSS Feed
MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.8 - Missing Authorization
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar <= 5.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via sonaar_audioplayer Shortcode
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar <= 5.7.0.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Deletion
MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via sonaar_audioplayer Shortcode
MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 4.10.1 - Unauthenticated Arbitrary File Download
MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.1 - Missing Authorization
MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 4.10 - Missing Authorization to Template Import
MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 2.4.1 - Multiple Admin+ Cross Site Scripting
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar Attack Surface
AJAX Handlers 24
WordPress Hooks 145
Maintenance & Trust
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar Maintenance & Trust
Maintenance Signals
Community Trust
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar Alternatives
Music Player for Elementor – Audio Player & Podcast Player
music-player-for-elementor
Audio Player for Elementor – the go-to plugin for adding MP3s, podcasts & playlists. Fully customizable, WooCommerce-ready, and mobile-friendly.
HTML5 jQuery Audio Player
html5-jquery-audio-player
Finally, a trendy looking audio player plugin. Works on all modern browsers including iPhone/iPad.
Liteweight Podcast – Host and Embed Podcast Episodes
liteweight-podcast
A lite weight Podcasting plugin for WordPress which contain lots of options and functionality to run your podcasting website.
Radiojar Audio Player
radiojar-player
Audio player plugin for Radiojar platform , just by dragging the widget or added shortcode [rj-player].
Serverless Radio
serverless-radio
A serverless MP3 linear streaming plugin that lets you create AutoDJ-like playlists from public MP3 folders — no VPS required.
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar Developer Profile
1 plugin · 20K total installs
How We Detect MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mp3-music-player-by-sonaar/admin/library/cmb-field-select2-master/css/select2.min.css/wp-content/plugins/mp3-music-player-by-sonaar/admin/library/cmb-field-select2-master/css/style.css/wp-content/plugins/mp3-music-player-by-sonaar/admin/library/cmb-field-select2-master/js/select2.min.js/wp-content/plugins/mp3-music-player-by-sonaar/admin/library/cmb-field-select2-master/js/script.js/wp-content/plugins/mp3-music-player-by-sonaar/admin/library/cmb-field-select2-master/js/script.jsmp3-music-player-by-sonaar/admin/library/cmb-field-select2-master/css/style.css?ver=mp3-music-player-by-sonaar/admin/library/cmb-field-select2-master/js/script.js?ver=HTML / DOM Fingerprints
pwcmb2_select2pwcmb2_selectpw_select2pw_multiselectdata-placeholder