Medium severity5.3NVD Advisory· Published Aug 17, 2024· Updated Jun 17, 2026
CVE-2023-4025
CVE-2023-4025
Description
The Radio Player plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_player function in versions up to, and including, 2.0.73. This makes it possible for unauthenticated attackers to update player instances.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4<=2.0.73+ 1 more
- (no CPE)range: <=2.0.73
- (no CPE)
- princeahmed/Radio Player – Live Shoutcast, Icecast and Any Audio Stream Playerv5Range: 0
Patches
Vulnerability mechanics
References
4- plugins.trac.wordpress.org/changeset/2942906/radio-player/trunk/includes/class-ajax.phpnvdPatch
- plugins.trac.wordpress.org/changeset/3048105nvdPatch
- www.wordfence.com/threat-intel/vulnerabilities/id/77409977-6822-4d14-9842-cb6a5aff2162nvdThird Party Advisory
- plugins.svn.wordpress.org/radio-player/tags/2.0.7/readme.txtnvdRelease Notes
News mentions
0No linked articles in our index yet.