CVE-2025-62885
- EPSS 0.06%
- Veröffentlicht 27.10.2025 01:33:44
- Zuletzt bearbeitet 20.01.2026 15:18:01
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RexTheme WP VR wpvr allows DOM-Based XSS.This issue affects WP VR: from n/a through <= 8.5.42.
CVE-2025-12005
- EPSS 0.05%
- Veröffentlicht 25.10.2025 05:31:23
- Zuletzt bearbeitet 27.10.2025 13:20:15
The WP VR – 360 Panorama and Free Virtual Tour Builder For WordPress plugin for WordPress is vulnerable to unauthorized access of data in all versions up to, and including, 8.5.41. This is due to the plugin not properly verifying that a user is autho...
CVE-2025-6350
- EPSS 0.03%
- Veröffentlicht 28.06.2025 03:21:59
- Zuletzt bearbeitet 07.07.2025 15:28:10
The WP VR – 360 Panorama and Free Virtual Tour Builder For WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘hotspot-hover’ parameter in all versions up to, and including, 8.5.32 due to insufficient input sanitizati...
CVE-2025-47452
- EPSS 0.09%
- Veröffentlicht 17.06.2025 15:01:34
- Zuletzt bearbeitet 17.06.2025 20:50:23
Unrestricted Upload of File with Dangerous Type vulnerability in RexTheme WP VR allows Upload a Web Shell to a Web Server. This issue affects WP VR: from n/a through 8.5.26.
CVE-2025-24730
- EPSS 0.15%
- Veröffentlicht 24.01.2025 18:15:47
- Zuletzt bearbeitet 24.01.2025 18:15:47
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rextheme WP VR allows DOM-Based XSS. This issue affects WP VR: from n/a through 8.5.14.
CVE-2024-49680
- EPSS 0.17%
- Veröffentlicht 19.11.2024 17:15:09
- Zuletzt bearbeitet 19.11.2024 21:57:32
Missing Authorization vulnerability in Rextheme WP VR allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP VR: from n/a through 8.5.5.
CVE-2024-49293
- EPSS 0.17%
- Veröffentlicht 21.10.2024 12:15:08
- Zuletzt bearbeitet 29.10.2024 15:07:39
Missing Authorization vulnerability in Rextheme WP VR allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP VR: from n/a through 8.5.4.
CVE-2023-6529
- EPSS 0.42%
- Veröffentlicht 08.01.2024 19:15:10
- Zuletzt bearbeitet 18.06.2025 17:15:26
The WP VR WordPress plugin before 8.3.15 does not authorisation and CSRF in a function hooked to admin_init, allowing unauthenticated users to downgrade the plugin, thus leading to Reflected or Stored XSS, as previous versions have such vulnerabiliti...
CVE-2023-40663
- EPSS 0.18%
- Veröffentlicht 27.09.2023 15:19:21
- Zuletzt bearbeitet 21.11.2024 08:19:55
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Rextheme WP VR plugin <= 8.3.4 versions.
CVE-2023-1414
- EPSS 0.06%
- Veröffentlicht 24.04.2023 19:15:09
- Zuletzt bearbeitet 04.02.2025 16:15:34
The WP VR WordPress plugin before 8.3.0 does not have authorisation and CSRF checks in various AJAX actions, one in particular could allow any authenticated users, such as subscriber to update arbitrary tours