Stored Cross-Site Scripting Vulnerability in WP VR Plugin for WordPress
CVE-2025-6350
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 28 June 2025
What is CVE-2025-6350?
The WP VR – 360 Panorama and Free Virtual Tour Builder for WordPress suffers from a Stored Cross-Site Scripting vulnerability via the 'hotspot-hover' parameter. This flaw arises from inadequate input sanitization and output escaping, allowing authenticated users with Contributor-level permissions and above to inject malicious web scripts. These scripts may execute on pages accessed by users, potentially compromising the integrity of the site and endangering user data. It's crucial for users of this plugin to implement updates to mitigate this security risk.
Affected Version(s)
WP VR – 360 Panorama and Free Virtual Tour Builder For WordPress * <= 8.5.32