🔐 CVE Alert

CVE-2024-49293

UNKNOWN 0.0

WordPress WP VR plugin <= 8.5.4 - Broken Access Control vulnerability

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Missing Authorization vulnerability in RexTheme WP VR wpvr allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP VR: from n/a through <= 8.5.4.

CWE CWE-862
Vendor rextheme
Product wp vr
Published Oct 21, 2024
Last Updated Apr 1, 2026
Stay Ahead of the Next One

Get instant alerts for rextheme wp vr

Be the first to know when new unknown vulnerabilities affecting rextheme wp vr are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

RexTheme / WP VR
0 ≤ 8.5.4

References

NVD ↗ CVE.org ↗ EPSS Data ↗
patchstack.com: https://patchstack.com/database/Wordpress/Plugin/wpvr/vulnerability/wordpress-wp-vr-plugin-8-5-4-broken-access-control-vulnerability?_s_id=cve

Credits

Trương Hữu Phúc (truonghuuphuc) | Patchstack Bug Bounty Program