CVE-2026-85415 PUBLISHED

Audio Player Block 1.1.0 - 1.6.2 - Contributor+ Stored XSS via Audio Download URL

Assigner: WPScan
Reserved: 03.09.2026 Published: 30.09.2026 Updated: 30.09.2026

The Audio Player Block WordPress plugin before 1.6.3 does not validate the scheme of a user-supplied URL before using it as a link target, allowing users with the Contributor role and above to store malicious JavaScript that executes in the session of any user who later triggers the link (such as an administrator or editor reviewing the post).

Product Status

Vendor Unknown
Product Audio Player Block
Versions Default: unaffected
  • affected from 1.1.0 to 1.6.3 (excl.)

Credits

  • Philipp Doblhofer finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE