Vulnerabilities (CVE)

Filtered by vendor Coderex Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-6529 1 Coderex 1 Wp Vr 2024-01-11 N/A 6.1 MEDIUM
The WP VR WordPress plugin before 8.3.15 does not authorisation and CSRF in a function hooked to admin_init, allowing unauthenticated users to downgrade the plugin, thus leading to Reflected or Stored XSS, as previous versions have such vulnerabilities.