Unrestricted File Upload Vulnerability in RexTheme's Web VR Plugin
CVE-2025-47452
9.9CRITICAL
What is CVE-2025-47452?
The RexTheme WP VR plugin is susceptible to an unrestricted file upload vulnerability, which allows an attacker to upload a web shell onto the server. This exploitation can lead to unauthorized access and manipulation of the server environment. Affected versions include all from n/a through 8.5.26, highlighting the need for immediate remediation to safeguard against potential threats.
Affected Version(s)
WP VR <= 8.5.26