CVE-2025-2103
Last modified
CVE-2025-2103 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. The SoundRise Music plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on theironMusic_ajax() function in all versions up to, and including, 1.6.11. This makes it possible for authenticated attackers, with subscriber-level access and above, to update arbitrary options on the WordPress site. EPSS estimates a 0.34% chance of exploitation in the next 30 days.
Description
The SoundRise Music plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on theironMusic_ajax() function in all versions up to, and including, 1.6.11. This makes it possible for authenticated attackers, with subscriber-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Irontemplates | Soundrise | < 1.7.1 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-2103?
How severe is CVE-2025-2103?
How do I fix CVE-2025-2103?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-21024Use of Implicit Intent for Sensitive Communication in Smart …5.5
- CVE-2025-21025Improper access control in MARsExemptionManager prior to SMR…4.4
- CVE-2025-21026Improper handling of insufficient permission in ImsService p…3.3
- CVE-2025-21027Improper verification of intent by broadcast receiver in Ims…4.4
- CVE-2025-21028Improper privilege management in ThemeManager prior to SMR S…5.5
- CVE-2025-21029Improper handling of insufficient permission in System UI pr…3.3
- CVE-2025-21030Improper handling of insufficient permission in AppPrelaunch…4.3
- CVE-2025-21031Improper access control in ImsService prior to SMR Sep-2025 …6.8
- CVE-2025-21032Improper access control in One UI Home prior to SMR Sep-2025…6.8
- CVE-2025-21033Improper access control in ContactProvider prior to SMR Sep-…5.5
- CVE-2025-21034Out-of-bounds write in libsavsvc.so prior to SMR Sep-2025 Re…7.8
- CVE-2025-21035Improper access control in Samsung Calendar prior to version…4.6
Are you affected by CVE-2025-2103?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
