CVE-2026-104386: WordPress WP VR plugin <= 9.1.3 - Broken Access Control vulnerability
Missing Authorization vulnerability in WPFunnels Team WP VR wpvr allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP VR: from n/a through 9.1.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WP VR pluginto a version that resolves this vulnerability.Fixed in 9.1.4
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The vulnerability requires low-level privileges. It is remotely reachable, but exploitation also requires user interaction.
Which deployments are affected?
WP VR versions through 9.1.3 are affected. The available information does not state whether a default configuration is vulnerable or identify a fixed version.
What is the potential impact?
Successful exploitation may allow limited impact to confidentiality, integrity, and availability, and the impact can extend beyond the vulnerable component's security scope.