cleantalk
Vulnerabilities and Security Researches

Html5 Audio Player – Audio Player for WordPress, CVE-2025-13999

CVE, Research URL

CVE-2025-13999

Published on
Dec 19, 2025
Research Description
The HTML5 Audio Player – The Ultimate No-Code Podcast, MP3 & Audio Player plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions from 2.4.0 up to, and including, 2.5.1 via the getIcyMetadata() function. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.
Affected versions
max 2.5.2.
Status
vulnerable