Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RexTheme WP VR wpvr allows DOM-Based XSS.This issue affects WP VR: from n/a through <= 8.5.14.
Published: 2025-01-24
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper neutralization of user input during web page generation, allowing attackers to inject malicious scripts that execute in the victim’s browser. This DOM‑based XSS enables an attacker to capture session cookies, deface content, or perform other client‑side attacks as the compromised user, exploiting the weakness defined by CWE‑79.

Affected Systems

The affected product is the WordPress WP VR plugin developed by RexTheme. All releases with version numbers up to and including 8.5.14 are vulnerable; this includes any earlier unspecified releases (n/a) that contain the legacy code paths used by the plugin.

Risk and Exploitability

With a CVSS score of 6.5 the vulnerability is considered moderate severity. The EPSS score of less than 1% and the absence from the CISA KEV catalog suggest a low probability of current exploitation. However, because the attack requires only a crafted request to the vulnerable plugin, an attacker with modest resources could still trigger the XSS if the plugin is accessible in a public site.

Generated by OpenCVE AI on May 1, 2026 at 18:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the WP VR plugin to version 8.5.15 or later, which removes the vulnerable input handling.
  • If an upgrade is not immediately possible, disable or delete the WP VR plugin to eliminate the attack surface.
  • Review and sanitize any user‑generated content in the plugin’s configuration or shortcodes, ensuring that all output is properly escaped against client‑side script injection.

Generated by OpenCVE AI on May 1, 2026 at 18:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3922 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rextheme WP VR allows DOM-Based XSS. This issue affects WP VR: from n/a through 8.5.14.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rextheme WP VR allows DOM-Based XSS. This issue affects WP VR: from n/a through 8.5.14. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RexTheme WP VR wpvr allows DOM-Based XSS.This issue affects WP VR: from n/a through <= 8.5.14.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 12 Feb 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Jan 2025 17:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rextheme WP VR allows DOM-Based XSS. This issue affects WP VR: from n/a through 8.5.14.
Title WordPress WP VR plugin <= 8.5.14 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Rextheme Wp Vr
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-12T23:48:07.470Z

Reserved: 2025-01-23T14:52:44.768Z

Link: CVE-2025-24730

cve-icon Vulnrichment

Updated: 2025-02-12T19:54:52.791Z

cve-icon NVD

Status : Deferred

Published: 2025-01-24T18:15:47.193

Modified: 2026-04-23T15:25:23.803

Link: CVE-2025-24730

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T18:30:05Z

Weaknesses