360 Javascript Viewer
360 Javascript Viewer has 3 disclosed vulnerabilities in the WordSec catalog, reported between 2023 and 2024; all 3 are fixed as of September 2026. Their average CVSS score is 4.7, and the most serious one scores 5.3 out of 10. 2024 was the busiest year with 2 disclosures.
The most common weakness is Missing Authorization, behind 2 of the records (67%). Other recurring categories include Cross-Site Scripting.
Every one of the 3 issues recorded for 360 Javascript Viewer has a vendor fix available, so running the current release closes all known holes.
3 independent researchers contributed these findings, one record each. 360 Javascript Viewer is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2023-48779360 Javascript Viewer <= 1.7.11 - Missing Authorization
Read the full analysisVulnerability Records

360 Javascript Viewer
Author
3DWeb
Features Full 360° view WooCommerce support Responsive design Zoom by wheel(mouse) or pinch(mobile) Unlimited presentations on a single page Just upload your images to your media library, no external service needed Variable amount of images, limit is 365 images Customize speed and inertia Reverse dragging Rotate to edges Custom frame format, no renaming of files Optional autorotation on start 1 is one rotation after start and 2 is 2 rotations and so on Reverse autorotation Speed autorotation otherwise it uses the speed of the viewer Custom start frame Stop at edges Use your own notifier Extra classes on images Float and margin for some placement control ShortCodes system, generate the shortcodes online for more control Widget Gutenberg block Elementor block Use ACF or WooCommerce product code for presentation Template function for developers Very lightweight (50kb) Support for WooCommerce Flatsome theme
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C