CVE-2024-7856
CVSS v3
8.1
HIGH
EPSS Score
19.2 %
exploit probability, as of 2026-10-04
CISA KEV
No
known exploited
Exploitation
—
SSVC status
Description
The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the removeTempFiles() function and insufficient path validation on the 'file' parameter in all versions up to, and including, 5.7.0.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary files which can make remote code execution possible when wp-config.php is deleted.
Technical details
- Published
- 2024-08-29
Frequently asked questions
What is CVE-2024-7856?
The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the removeTempFiles() function and insufficient path validation on the 'file' parameter in all versions up to, and including, 5.7.0.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary files which can make remote code execution possible when wp-config.php is deleted.
Is CVE-2024-7856 actively exploited?
Active exploitation of CVE-2024-7856 has not been confirmed. Its EPSS score was 19.2% on 2026-10-04, the estimated probability of exploitation in the next 30 days.
What is the CVSS score for CVE-2024-7856?
CVE-2024-7856 has a CVSS v3 base score of 8.1 (HIGH severity).
Is CVE-2024-7856 affecting your environment?
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
No credit card required · 50 free checks/month · Free API key
Other 2024 vulnerabilities worth triaging
Ranked by exploit probability (EPSS).