Boletines de Vulnerabilidades |
CVE-2026-1219 |
|
| Software afectado | WORDPRESS |
| The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions 4.0 to 5.10 via the 'load_track_note_ajax' due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to view the contents of private posts. | |
Link: |
|
| https://nvd.nist.gov/vuln/detail/CVE-2026-1219 | |














