Stored Cross-Site Scripting Vulnerability in WP VR Plugin for WordPress
CVE-2025-6350
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 28 June 2025
What is CVE-2025-6350?
The WP VR β 360 Panorama and Free Virtual Tour Builder for WordPress suffers from a Stored Cross-Site Scripting vulnerability via the 'hotspot-hover' parameter. This flaw arises from inadequate input sanitization and output escaping, allowing authenticated users with Contributor-level permissions and above to inject malicious web scripts. These scripts may execute on pages accessed by users, potentially compromising the integrity of the site and endangering user data. It's crucial for users of this plugin to implement updates to mitigate this security risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WP VR β 360 Panorama and Free Virtual Tour Builder For WordPress * <= 8.5.32
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved