First published: Mon Apr 24 2023(Updated: )
The WP VR WordPress plugin before 8.3.0 does not have authorisation and CSRF checks in various AJAX actions, one in particular could allow any authenticated users, such as subscriber to update arbitrary tours
Credit: contact@wpscan.com contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Rextheme WP VR | <8.3.0 | |
Coderex WP VR | <8.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-1414.
The severity of CVE-2023-1414 is medium (4.3).
The WP VR WordPress plugin vulnerability allows any authenticated users, such as subscribers, to update arbitrary tours.
CVE-2023-1414 affects WP VR WordPress plugin versions up to but excluding 8.3.0.
Yes, you can find a reference for CVE-2023-1414 at https://wpscan.com/vulnerability/d61d4be7-9251-4c62-8fb7-8a456aa6969e.