The WP VR WordPress plugin before 8.3.15 does not authorisation and CSRF in a function hooked to admin_init, allowing unauthenticated users to downgrade the plugin, thus leading to Reflected or Stored XSS, as previous versions have such vulnerabilities.
| Software | From | Fixed in |
|---|---|---|
| rextheme / wp_vr | - | 8.3.15 |