Description
The WP VR WordPress plugin before 8.3.15 does not authorisation and CSRF in a function hooked to admin_init, allowing unauthenticated users to downgrade the plugin, thus leading to Reflected or Stored XSS, as previous versions have such vulnerabilities.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-58760 | The WP VR WordPress plugin before 8.3.15 does not authorisation and CSRF in a function hooked to admin_init, allowing unauthenticated users to downgrade the plugin, thus leading to Reflected or Stored XSS, as previous versions have such vulnerabilities. |
References
History
Wed, 18 Jun 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 31 Oct 2024 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rextheme
Rextheme wp Vr |
|
| CPEs | cpe:2.3:a:rextheme:wp_vr:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Coderex
Coderex wp Vr |
Rextheme
Rextheme wp Vr |
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-06-18T16:50:52.089Z
Reserved: 2023-12-05T16:45:09.724Z
Link: CVE-2023-6529
Updated: 2024-08-02T08:35:14.624Z
Status : Modified
Published: 2024-01-08T19:15:10.320
Modified: 2025-06-18T17:15:26.923
Link: CVE-2023-6529
No data.
OpenCVE Enrichment
No data.
EUVD