Missing Authorization Flaw in bPlugins 3D Viewer - Embed 3D Models
CVE-2026-40729

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
15 April 2026

What is CVE-2026-40729?

A missing authorization vulnerability exists in the bPlugins 3D Viewer – Embed 3D Models plugin, which allows attackers to exploit incorrectly configured access control settings. This flaw permits unauthorized access to sensitive features, endangering user data and site security. It affects versions up to 1.8.5, highlighting the need for users to upgrade to more secure versions to mitigate potential risks.

Affected Version(s)

3D viewer – Embed 3D Models 0 <= 1.8.5

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nabil Irawan | Patchstack Bug Bounty Program
.