Beveiligingsadvies

CVE-2023-6529

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2024-01-08 19:00:26
Laatst bijgewerkt 2025-06-18 16:50:52
Toegewezen door WPScan
CVSS-score 6.1
Status PUBLISHED

Beschrijving

The WP VR WordPress plugin before 8.3.15 does not authorisation and CSRF in a function hooked to admin_init, allowing unauthenticated users to downgrade the plugin, thus leading to Reflected or Stored XSS, as previous versions have such vulnerabilities.