Vulnerability index

Browse CVEs

8 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2025-6350 The WP VR – 360 Panorama and Free Virtual Tour Builder For WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘hotsp… Wp Vr 8.5.33+ Fix from $1,6002025-06-28 MEDIUM 5.4 CVE-2024-49293 Missing Authorization vulnerability in RexTheme WP VR wpvr allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects… Wp Vr after 8.5.4 Fix from $1,6002024-10-21 MEDIUM 6.1 CVE-2023-6529 The WP VR WordPress plugin before 8.3.15 does not authorisation and CSRF in a function hooked to admin_init, allowing unauthenticated users to downgr… Wp Vr 8.3.15+ Fix from $1,6002024-01-08 MEDIUM 6.1 CVE-2023-40663 Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Rextheme WP VR plugin <= 8.3.4 versions. Wp Vr after 8.3.4 Fix from $1,6002023-09-27 MEDIUM 6.1 CVE-2022-47449 Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in RexTheme Cart Lift – Abandoned Cart Recovery for WooCommerce and EDD plugin <= 3.1.5 ve… Cart Lift Abandoned Cart Recovery For Woocommerce And Edd after 3.1.5 Fix from $1,6002023-05-04 MEDIUM 6.1 CVE-2023-1413 The WP VR WordPress plugin before 8.2.9 does not sanitise and escape some parameters before outputting them back in the page, leading to a Reflected … Wp Vr 8.2.9+ Fix from $1,6002023-04-17 HIGH 8.8 CVE-2023-25708 Cross-Site Request Forgery (CSRF) vulnerability in Rextheme WP VR – 360 Panorama and Virtual Tour Builder For WordPress plugin <= 8.2.7 versions. Wp Vr 8.2.8+ Fix from $1,9502023-03-15 MEDIUM 5.4 CVE-2023-0174 The WP VR WordPress plugin before 8.2.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post wher… Wp Vr 8.2.7+ Fix from $1,6002023-02-06