Known CVE
WordPress AudioIgniter <= 2.0.2 - Unauthenticated IDOR
The AudioIgniter plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 2.0.2. The handle_playlist_endpoint() function accepted a user-controlled playlist ID and returned track data without authentication.
CVE-2026-8679
High2026CVSS 7.5CWE-639
cve2026 · wordpress · wp-plugin · audioigniter · idor · exposure · wp
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website