CVE-2025-62885: WordPress WP VR plugin <= 8.5.48 - Cross Site Scripting (XSS) vulnerability
Published Oct 27, 2025
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RexTheme WP VR wpvr allows DOM-Based XSS.This issue affects WP VR: from n/a through <= 8.5.48.
Affected Software
1 affected component
Rextheme WP VR<=8.5.48
Event History
Oct 27, 2025
CVE Published
via MITRE·01:33 AM
Data Sourced
via MITRE·01:33 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-62885?
CVE-2025-62885 is classified as a high severity Cross-site Scripting (XSS) vulnerability.
2
How do I fix CVE-2025-62885?
To fix CVE-2025-62885, update the WP VR plugin to the latest version beyond 8.5.42.
3
What is the impact of CVE-2025-62885?
The impact of CVE-2025-62885 allows attackers to execute arbitrary scripts in the context of a user's browser.
4
Which versions of WP VR are affected by CVE-2025-62885?
WP VR versions from n/a through 8.5.42 are affected by CVE-2025-62885.
5
What type of vulnerability is CVE-2025-62885?
CVE-2025-62885 is an example of a DOM-Based Cross-site Scripting (XSS) vulnerability.