PT-2025-39939 · WordPress · All In One Music Player

Dj

+1

·

Published

2025-09-30

·

Updated

2025-09-30

·

CVE-2025-8559

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions All in One Music Player plugin for WordPress versions prior to 1.3.2
Description The All in One Music Player plugin for WordPress is susceptible to a Path Traversal issue through the theme parameter. This allows authenticated attackers with Contributor-level access or higher to read files on the server, potentially exposing sensitive information. The vulnerable API endpoint is not specified. The vulnerable parameter is theme.
Recommendations Update the All in One Music Player plugin to version 1.3.2 or later.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-8559

Affected Products

All In One Music Player