Stored Cross-Site Scripting Vulnerability in WP VR Plugin for WordPress
CVE-2025-6350

6.4MEDIUM

What is CVE-2025-6350?

The WP VR – 360 Panorama and Free Virtual Tour Builder for WordPress suffers from a Stored Cross-Site Scripting vulnerability via the 'hotspot-hover' parameter. This flaw arises from inadequate input sanitization and output escaping, allowing authenticated users with Contributor-level permissions and above to inject malicious web scripts. These scripts may execute on pages accessed by users, potentially compromising the integrity of the site and endangering user data. It's crucial for users of this plugin to implement updates to mitigate this security risk.

Affected Version(s)

WP VR – 360 Panorama and Free Virtual Tour Builder For WordPress * <= 8.5.32

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Craig Smith
.
CVE-2025-6350 : Stored Cross-Site Scripting Vulnerability in WP VR Plugin for WordPress