CVE-2025-6350: WP VR – 360 Panorama and Free Virtual Tour Builder For WordPress <= 8.5.32 - Authenticated (Contributor+) Stored Cross-Site Scripting
The WP VR – 360 Panorama and Free Virtual Tour Builder For WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘hotspot-hover’ parameter in all versions up to, and including, 8.5.32 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WP VR – 360 Panorama and Free Virtual Tour Builder For WordPressto a version that resolves this vulnerability.Fixed in 8.5.32 - Compensating control
Restrict authenticated access to the plugin’s contributor-level features (Contributor+), since exploitation requires Contributor-level access and above.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6350?
CVE-2025-6350 is classified as a high severity vulnerability due to the potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2025-6350?
To fix CVE-2025-6350, update the WP VR – 360 Panorama and Free Virtual Tour Builder plugin to version 8.5.33 or later.
What versions are affected by CVE-2025-6350?
CVE-2025-6350 affects all versions of the WP VR – 360 Panorama and Free Virtual Tour Builder plugin up to and including version 8.5.32.
What type of vulnerability is CVE-2025-6350?
CVE-2025-6350 is a Stored Cross-Site Scripting (XSS) vulnerability affecting the WP VR plugin.
What is the impact of exploiting CVE-2025-6350?
Exploiting CVE-2025-6350 allows attackers to execute arbitrary JavaScript code in the context of the user’s session.