Ogulo – 360° Tour
Ogulo – 360° Tour has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Ogulo – 360° Tour has a vendor fix available, so running the current release closes it.
All of these findings were reported by Peter Thaleikis. Ogulo – 360° Tour is installed on roughly 40 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.
CVE-2025-9131Ogulo – 360° Tour <= 1.0.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via slug Parameter
Read the full analysisVulnerability Records

Ogulo – 360° Tour
Author
ogulo
Any real estate brokerage, whether private or commercial, is a process characterized by an average of at least 80% idleness and – most importantly – inefficient mass viewing. This is mainly due to the fact that real estate is not mobile. A real absurdity in today’s world! This is why we have made it our mission to provide estate agents and real estate agents with a simple and affordable tool that allows anyone to make real estate mobile in the form of a virtual tour. Ogulo mobilises estate agents and all other people involved in the mediation process (sellers, buyers, tenants and subcontractors) to free them from said inefficiencies. Ogulo 360° tours allow your prospective buyers to have a complete insight into the property. This reduces unnecessary appointments and allows for greater flexibility in offering your property to your prospects.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C