CVE-2025-62885
- EPSS 0.03%
- Veröffentlicht 27.10.2025 01:33:44
- Zuletzt bearbeitet 15.04.2026 00:35:42
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RexTheme WP VR wpvr allows DOM-Based XSS.This issue affects WP VR: from n/a through <= 8.5.48.
CVE-2025-12005
- EPSS 0.03%
- Veröffentlicht 25.10.2025 05:31:23
- Zuletzt bearbeitet 15.04.2026 00:35:42
The WP VR – 360 Panorama and Free Virtual Tour Builder For WordPress plugin for WordPress is vulnerable to unauthorized access of data in all versions up to, and including, 8.5.41. This is due to the plugin not properly verifying that a user is autho...
CVE-2025-6350
- EPSS 0.04%
- Veröffentlicht 28.06.2025 03:21:59
- Zuletzt bearbeitet 07.07.2025 15:28:10
The WP VR – 360 Panorama and Free Virtual Tour Builder For WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘hotspot-hover’ parameter in all versions up to, and including, 8.5.32 due to insufficient input sanitizati...
CVE-2025-47452
- EPSS 0.04%
- Veröffentlicht 17.06.2025 15:01:34
- Zuletzt bearbeitet 15.04.2026 00:35:42
Unrestricted Upload of File with Dangerous Type vulnerability in RexTheme WP VR wpvr allows Upload a Web Shell to a Web Server.This issue affects WP VR: from n/a through <= 8.5.26.
CVE-2025-24730
- EPSS 0.14%
- Veröffentlicht 24.01.2025 18:15:47
- Zuletzt bearbeitet 15.04.2026 00:35:42
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RexTheme WP VR wpvr allows DOM-Based XSS.This issue affects WP VR: from n/a through <= 8.5.14.
CVE-2024-49680
- EPSS 0.15%
- Veröffentlicht 19.11.2024 17:15:09
- Zuletzt bearbeitet 15.04.2026 00:35:42
Missing Authorization vulnerability in RexTheme WP VR wpvr allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP VR: from n/a through <= 8.5.5.
CVE-2024-49293
- EPSS 0.22%
- Veröffentlicht 21.10.2024 12:15:08
- Zuletzt bearbeitet 01.04.2026 16:18:37
Missing Authorization vulnerability in RexTheme WP VR wpvr allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP VR: from n/a through <= 8.5.4.
CVE-2023-6529
- EPSS 0.42%
- Veröffentlicht 08.01.2024 19:15:10
- Zuletzt bearbeitet 18.06.2025 17:15:26
The WP VR WordPress plugin before 8.3.15 does not authorisation and CSRF in a function hooked to admin_init, allowing unauthenticated users to downgrade the plugin, thus leading to Reflected or Stored XSS, as previous versions have such vulnerabiliti...
CVE-2023-40663
- EPSS 0.18%
- Veröffentlicht 27.09.2023 15:19:21
- Zuletzt bearbeitet 21.11.2024 08:19:55
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Rextheme WP VR plugin <= 8.3.4 versions.
CVE-2023-1414
- EPSS 0.06%
- Veröffentlicht 24.04.2023 19:15:09
- Zuletzt bearbeitet 04.02.2025 16:15:34
The WP VR WordPress plugin before 8.3.0 does not have authorisation and CSRF checks in various AJAX actions, one in particular could allow any authenticated users, such as subscriber to update arbitrary tours