S4E just found a high online generic sql injection vulnerability scanner
high·Product Based Web Vulnerabilities·Updated May 25, 2026

CVE-2026-8679 Scanner

CVE-2026-8679 Scanner - Insecure Direct Object References (IDOR) vulnerability in WordPress AudioIgniter

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2026-8679
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.

The AudioIgniter plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 2.0.2. This is due to the handle_playlist_endpoint() function (hooked to template_redirect) accepting a user-controlled playlist ID via the audioigniter_playlist_id query var or the /audioigniter/playlist/{id}/ rewrite rule and returning playlist track data without performing any authentication, capability, or post_status check — only the post_type is validated. This makes it possible for unauthenticated attackers to view track metadata (titles, artists, audio URLs, buy links, download URLs, and cover images) of any playlist on the site, including those in draft, private, pending, or trash status.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
AudioIgniter Music Playerby cssigniterteam
0
Updated Aug 5, 2026View on NVD →
Detail

The AudioIgniter plugin for WordPress is widely used by website owners to easily integrate audio playlists and enhance user experience. Developed for WordPress, it allows users to create, manage, and distribute audio playlists within their websites. This plugin is particularly useful for bloggers, musicians, and podcasters who aim to share audio content with their audience. Often utilized for its user-friendly interface, AudioIgniter provides a seamless method to embed audio. It supports various music hosting services, making it a popular choice for those in the entertainment and music industries. Its widespread use makes it essential for securing against vulnerabilities to protect both user data and site integrity.

The vulnerability in question allows unauthorized individuals to exploit Insecure Direct Object References (IDOR) within the WordPress AudioIgniter plugin. An unauthenticated attacker can manipulate input parameters to access sensitive data. This vulnerability could lead to information disclosure, providing access to private and draft content unnecessarily. The plugin allows users to control playlist IDs, which further amplifies the risk when exploited. As a result, private playlist metadata, including titles, audio tracks, and subtitles, could be exposed to unauthorized entities. Mitigating this risk requires immediate attention to the plugin's authentication protocols.

Technical details indicate that the "handle_playlist_endpoint()" function within the plugin accepts user-controlled playlist IDs without proper authentication. This endpoint's lack of validation allows any user to retrieve sensitive playlist information. The underlying issue stems from expecting trusted IDs from users without verification, thereby enabling IDOR attacks. A malicious actor could directly interact with the application endpoints, bypassing security controls. The vulnerable endpoint returns track data that should be restricted, highlighting a critical design flaw. The embedded function in the plugin is the primary attack vector, thus necessitating a rigorous review and rectification to prevent data exploitation.

If exploited, the vulnerability could expose sensitive user and application data, consequently leading to unauthorized access to private or draft content. This data exposure could adversely affect user privacy and compromise site integrity. Organizations relying on this plugin may find their content accessible to unauthorized users, leading to potential reputation damage. An attack leveraging this vulnerability may also further exploit related weaknesses within the site. Overall, this could undermine trust among content creators and users relying on secure access to personal media. The potential loss of intellectual property should prompt immediate corrective actions.

REFERENCES

Solution Advice
  • Update the AudioIgniter plugin to the latest version immediately.
  • Implement authentication checks for user input involving playlist IDs.
  • Conduct regular security audits to identify and remediate similar vulnerabilities.
  • Educate developers on secure coding practices, particularly with IDOR vulnerabilities.
  • Monitor access logs for suspicious activities to detect potential exploitation attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.