Description
Cross-Site Request Forgery (CSRF) vulnerability in SwiftXR SwiftXR (3D/AR/VR) Viewer swiftxr-3darvr-viewer allows Cross Site Request Forgery.This issue affects SwiftXR (3D/AR/VR) Viewer: from n/a through <= 1.0.7.
Published: 2025-04-04
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Cross‑Site Request Forgery (CSRF) in the SwiftXR (3D/AR/VR) Viewer plugin allows an attacker to execute actions on the site without the user’s consent. The flaw is rooted in the lack of proper CSRF protection, which is a weakness identified as CWE‑352. A successful exploit could let an attacker submit requests that perform functions such as modifying settings, adding content, or otherwise altering the site state, potentially leading to data loss or service disruption if sensitive operations are affected.

Affected Systems

The vulnerability impacts the SwiftXR (3D/AR/VR) Viewer plugin for WordPress, affecting all releases from the earliest version up through 1.0.7. Users who have not applied the vendor’s latest patch or replacement for the plugin are at risk.

Risk and Exploitability

The CVSS score is 5.4, indicating moderate severity, while the EPSS score is below 1 %, suggesting that exploitation is unlikely in the near term. The vulnerability is not listed in CISA’s KEV catalog, so there is no public evidence of active exploitation. The likely attack vector involves a user who is already authenticated: a malicious site could craft and send a request that the victim’s browser automatically submits, leveraging the victim’s credentials to perform unintended actions.

Generated by OpenCVE AI on May 1, 2026 at 11:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade SwiftXR (3D/AR/VR) Viewer to a version newer than 1.0.7 (e.g., 1.0.8 or later).
  • If upgrading is not immediately possible, disable the SwiftXR plugin on the site to prevent any unauthorized requests.
  • Implement additional CSRF protection by ensuring all plugin actions validate WordPress nonces or by installing a CSRF protection plugin to enforce token checks on all authenticated requests.

Generated by OpenCVE AI on May 1, 2026 at 11:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-9799 Cross-Site Request Forgery (CSRF) vulnerability in SwiftXR SwiftXR (3D/AR/VR) Viewer allows Cross Site Request Forgery. This issue affects SwiftXR (3D/AR/VR) Viewer: from n/a through 1.0.7.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in SwiftXR SwiftXR (3D/AR/VR) Viewer allows Cross Site Request Forgery. This issue affects SwiftXR (3D/AR/VR) Viewer: from n/a through 1.0.7. Cross-Site Request Forgery (CSRF) vulnerability in SwiftXR SwiftXR (3D/AR/VR) Viewer swiftxr-3darvr-viewer allows Cross Site Request Forgery.This issue affects SwiftXR (3D/AR/VR) Viewer: from n/a through <= 1.0.7.
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L'}


Fri, 04 Apr 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 04 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in SwiftXR SwiftXR (3D/AR/VR) Viewer allows Cross Site Request Forgery. This issue affects SwiftXR (3D/AR/VR) Viewer: from n/a through 1.0.7.
Title WordPress SwiftXR (3D/AR/VR) Viewer plugin <= 1.0.7 - Cross Site Request Forgery (CSRF) vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:19.748Z

Reserved: 2025-04-04T10:02:07.011Z

Link: CVE-2025-32248

cve-icon Vulnrichment

Updated: 2025-04-04T20:13:59.356Z

cve-icon NVD

Status : Deferred

Published: 2025-04-04T16:15:33.973

Modified: 2026-04-23T15:28:49.983

Link: CVE-2025-32248

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T11:15:15Z

Weaknesses