WordPress Plugin Vulnerabilities

Outdated VRView Library Used, Leading to Reflected XSS

Description

The vrview (<= 1.1.3) and wp-vr-view (<= 1.6) plugins are using an outdated version of the VRView library (< 2.0.2), which is affected by a reflected cross-site scripting issue.

Proof of Concept

Affects Plugins

No known fix
No known fix

References

Classification

Type
XSS
CWE
CVSS

Miscellaneous

Original Researcher
Federico Fazzi (mindedsecurity.com)
Verified
Yes

Timeline

Publicly Published
2018-04-23 (about 8 years ago)
Added
2020-06-08 (about 5 years ago)
Last Updated
2021-09-06 (about 4 years ago)

Other