Impact
The WP VR WordPress plugin suffers from a broken access control flaw that allows users without proper authorization to exploit incorrectly configured security levels. The vulnerability enables an attacker to access or modify privileged functions or data normally restricted to administrators. This can lead to unauthorized viewing of sensitive information, unauthorized content manipulation, or configuration changes that compromise site integrity.
Affected Systems
All versions of the WP VR plugin up through 9.1.3 are affected. The plugin is developed by the WPFunnels Team and is distributed as a WordPress plugin. Users running 9.1.3 or any prior version should consider themselves impacted.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. The absence of an EPSS score and the fact that it is not listed in the CISA KEV catalog suggest that, while the vulnerability is exploitable, it may not be actively targeted in the wild. Attacks would likely originate from the web interface or API endpoints of the plugin and would require at least an authenticated user with limited privileges to progress to higher privileges, making the attack vector relatively low to moderate. Nonetheless, organizations should treat it as a high priority due to potential privilege escalation.
OpenCVE Enrichment