Extension WordPress
Vulnérabilités WP VR – 360 Panorama and Virtual Tour Builder
Cette page rassemble les failles publiées pour WP VR – 360 Panorama and Virtual Tour Builder, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WP VR – 360 Panorama and Virtual Tour Builder
16 fiches
WP VR – 360 Panorama and Free Virtual Tour Builder For WordPress <= 8.5.41 – Improper Authorization to Authenticated (Contributor+) Plugin Settings Update
The WP VR – 360 Panorama and Free Virtual Tour Builder For WordPress plugin for WordPress is vulnerable to unauthorized access of data in all versions up to, and including, 8.5.41. This is due to the plugin not…
*-8.5.41
8.5.42
24/10/2025
WP VR – 360 Panorama and Free Virtual Tour Builder For WordPress <= 8.5.32 – Authenticated (Contributor+) Stored Cross-Site Scripting
The WP VR – 360 Panorama and Free Virtual Tour Builder For WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘hotspot-hover’ parameter in all versions up to, and including, 8.5.32 due to insufficient input…
*-8.5.32
8.5.33
27/06/2025
VR <= 8.5.48 – Authenticated (Contributor+) Stored Cross-Site Scripting
The VR plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 8.5.48 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,…
*-8.5.48
8.5.49
27/06/2025
WP VR <= 8.5.26 – Authenticated (Contributor+) Arbitrary File Upload
The WP VR – 360 Panorama and Free Virtual Tour Builder For WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 8.5.26. This makes…
*-8.5.26
8.5.27
12/06/2025
WP VR <= 8.5.14 – Authenticated (Contributor+) Stored Cross-Site Scripting
The WP VR plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 8.5.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…
*-8.5.14
8.5.15
24/01/2025
WP VR <= 8.5.5 – Missing Authorization
The WP VR plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpvr_review_request() function among others in versions up to, and including, 8.5.5. This makes it possible for authenticated…
*-8.5.5
8.5.6
21/10/2024
WP VR <= 8.5.4 – Missing Authorization
The WP VR plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 8.5.4. This makes it possible for authenticated attackers, with contributor-level access and…
*-8.5.4
8.5.5
15/10/2024
WP VR <= 8.3.14 – Missing Authorization to Plugin Version Downgrade
The WP VR – 360 Panorama and Virtual Tour Builder For WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the trigger_rollback() function in all versions up to, and including, 8.3.14.…
*-8.3.14
8.3.15
14/12/2023
WP VR <= 8.3.4 – Reflected Cross-Site Scripting
The WP VR plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via tab parameters in versions up to, and including, 8.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
*-8.3.4
8.3.5
18/08/2023
Freemius SDK <= 2.5.9 – Reflected Cross-Site Scripting via fs_request_get
The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
1.0.1
1.0.2
18/07/2023
WP VR <= 8.2.9 – Missing Authorization
The WP VR plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on an AJAX action in versions up to, and including, 8.2.9. This makes it possible for subscriber-level attackers to…
*-8.2.9
8.3.0
29/03/2023
WP VR <= 8.2.8 – Reflected Cross-Site Scripting
The WP VR plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'active_tab', 'scene', and 'hotspot' parameters in versions up to, and including, 8.2.8 due to insufficient input sanitization and output escaping. This makes it possible…
*-8.2.5
8.2.6
22/03/2023
WP VR <= 8.2.7 – Cross-Site Request Forgery
The WP VR plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.2.7. This is due to missing or incorrect nonce validation on the 'wpvr_role_management' function. This makes it possible for unauthenticated…
*-8.2.7
8.2.8
14/02/2023
WP VR <= 8.2.6 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The WP VR plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to, and including, 8.2.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it…
*-8.2.6
8.2.7
12/01/2023
Appsero <= 1.2.1 – Missing Authorization
The Appsero analytics tool used in several plugins is vulnerable to authorization bypass due to a missing capability check on the uninstall_reason_submission function used for feedback submission in versions up to, and including, 1.2.1. This makes it possible…
*-8.2.5
8.2.6
16/12/2022
Appsero <= 1.2.0 – Cross-Site Request Forgery
The Appsero analytics tool used in several plugins is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the uninstall_reason_submission function used for feedback submission in versions up to, and including, 1.2.0. This makes it…
*-8.2.5
8.2.6
14/12/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.