Vulnerability index

Browse CVEs

8 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Wp Vr MEDIUM 5.4
CVE-2025-6350

The WP VR – 360 Panorama and Free Virtual Tour Builder For WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘hotsp…

Fix: 8.5.33+
Fix from $1,600 2025-06-28
Wp Vr MEDIUM 5.4
CVE-2024-49293

Missing Authorization vulnerability in RexTheme WP VR wpvr allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects…

Fix: after 8.5.4
Fix from $1,600 2024-10-21
Wp Vr MEDIUM 6.1
CVE-2023-6529

The WP VR WordPress plugin before 8.3.15 does not authorisation and CSRF in a function hooked to admin_init, allowing unauthenticated users to downgr…

Fix: 8.3.15+
Fix from $1,600 2024-01-08
Wp Vr MEDIUM 6.1
CVE-2023-40663

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Rextheme WP VR plugin <= 8.3.4 versions.

Fix: after 8.3.4
Fix from $1,600 2023-09-27
Cart Lift Abandoned Cart Recovery For Woocommerce And Edd MEDIUM 6.1
CVE-2022-47449

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in RexTheme Cart Lift – Abandoned Cart Recovery for WooCommerce and EDD plugin <= 3.1.5 ve…

Fix: after 3.1.5
Fix from $1,600 2023-05-04
Wp Vr MEDIUM 6.1
CVE-2023-1413

The WP VR WordPress plugin before 8.2.9 does not sanitise and escape some parameters before outputting them back in the page, leading to a Reflected …

Fix: 8.2.9+
Fix from $1,600 2023-04-17
Wp Vr HIGH 8.8
CVE-2023-25708

Cross-Site Request Forgery (CSRF) vulnerability in Rextheme WP VR – 360 Panorama and Virtual Tour Builder For WordPress plugin <= 8.2.7 versions.

Fix: 8.2.8+
Fix from $1,950 2023-03-15
Wp Vr MEDIUM 5.4
CVE-2023-0174

The WP VR WordPress plugin before 8.2.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post wher…

Fix: 8.2.7+
Fix from $1,600 2023-02-06