Description
Missing Authorization vulnerability in WPFunnels Team WP VR wpvr allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP VR: from n/a through 9.1.3.
Published: 2026-10-05
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access
Action: Patch Immediately
AI Analysis

Impact

The WP VR WordPress plugin suffers from a broken access control flaw that allows users without proper authorization to exploit incorrectly configured security levels. The vulnerability enables an attacker to access or modify privileged functions or data normally restricted to administrators. This can lead to unauthorized viewing of sensitive information, unauthorized content manipulation, or configuration changes that compromise site integrity.

Affected Systems

All versions of the WP VR plugin up through 9.1.3 are affected. The plugin is developed by the WPFunnels Team and is distributed as a WordPress plugin. Users running 9.1.3 or any prior version should consider themselves impacted.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity. The absence of an EPSS score and the fact that it is not listed in the CISA KEV catalog suggest that, while the vulnerability is exploitable, it may not be actively targeted in the wild. Attacks would likely originate from the web interface or API endpoints of the plugin and would require at least an authenticated user with limited privileges to progress to higher privileges, making the attack vector relatively low to moderate. Nonetheless, organizations should treat it as a high priority due to potential privilege escalation.

Generated by OpenCVE AI on October 5, 2026 at 10:29 UTC.

Remediation

Vendor Solution

Update the WordPress WP VR plugin to the latest available version (at least 9.1.4).


OpenCVE Recommended Actions

  • Apply the latest plugin update (9.1.4 or newer) to eliminate the broken access control.
  • Review user role permissions in WordPress to ensure only trusted administrators have access to plugin settings and privileged endpoints.
  • If an immediate update is not possible, temporarily block or restrict the plugin’s administrative endpoints through your web server or CMS configuration until the fix is applied.

Generated by OpenCVE AI on October 5, 2026 at 10:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 09:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in WPFunnels Team WP VR wpvr allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP VR: from n/a through 9.1.3.
Title WordPress WP VR plugin <= 9.1.3 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-05T08:34:19.528Z

Reserved: 2026-10-02T00:22:13.105Z

Link: CVE-2026-104386

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T09:17:07.380

Modified: 2026-10-05T09:17:07.380

Link: CVE-2026-104386

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T10:30:18Z

Weaknesses