Panorama – turn photos into immersive virtual tours
Panorama – turn photos into immersive virtual tours has 3 disclosed vulnerabilities in the WordSec catalog, reported between 2022 and 2026; all 3 are fixed as of August 2026. Their average CVSS score is 6.6, and the most serious one scores 7.5 out of 10. Severity breakdown: 0 critical and 1 high.
The most common weakness is Cross-Site Scripting, behind 1 of the records (33%). Other recurring categories include Missing Authorization, PHP Remote File Inclusion.
Every one of the 3 issues recorded for Panorama – turn photos into immersive virtual tours has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. Panorama – turn photos into immersive virtual tours is installed on roughly 2,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2026-57647Panorama – 360 degree Virtual Tour, Panoramic Image viewer and More <= 1.6.1 - Authenticated (Contributor+) Local File Inclusion
Read the full analysisVulnerability Records

Panorama – turn photos into immersive virtual tours
Author
bPlugins
Turn flat photos into immersive 360° experiences – virtual tours, panoramic images, and 360° videos your visitors can explore, no technical knowledge required. See Live Demos | Get Pro Version Why Panorama? Panorama lets you embed panoramic photos and videos in posts, pages, widget areas, and WooCommerce product pages. It comes with everything you need to make the most of your panoramic pictures – and anyone can use it easily without any technical knowledge. The plugin displays 360° images, 3D images, videos, and panoramic galleries seamlessly. With dedicated Gutenberg blocks, shortcodes, and WooCommerce integration, you can place immersive media anywhere on your site. The free version includes fully functional blocks for all media types: 360° virtual tours (up to 2 scenes and 3 hotspots), interactive product hotspots (up to 3 spots), basic Google Street View embedding, and WooCommerce integration for 360° images and product spots. Free Features WooCommerce Integration (Basic): Embed 360° images and product hotspots directly into WooCommerce product pages. 8 Gutenberg Blocks: Image 360°, Image 3D, Video, Video 360°, Google Street View, Gallery, Virtual Tour, and Product Spot. 360° Virtual Tour: Connect up to 2 scenes with Info, Scene, and Link hotspots. Product Spot: Highlight product details with interactive hotspots (up to 3 spots). Google Street View (Basic): Embed Google Street View panoramas easily by entering the Panorama ID. Media Uploads: Upload and display panoramic images and videos from the WordPress media library. Auto-Rotation: Enable auto-rotate and customize rotation speed in degrees per second. Shortcode API & Embed URLs: Generate shortcodes to place viewers anywhere, and use public URLs to share content. Elementor & Page Builder Compatible: Works seamlessly with Elementor and other builders using shortcodes. Lightweight & Fast: Optimized performance for fast loading times without bloat. Pro Version Upgrade to Panorama Pro to unlock: WooCommerce Video Integration: Add 360° and standard panoramic videos directly to WooCommerce product galleries. Unlimited Virtual Tours: Connect unlimited scenes with Info, Scene, Link, Image, and Video hotspots. Initial View Settings: Set precise starting angles (Pitch, Yaw, and Field of View / Zoom) for panoramas. Advanced Navigation & Interaction: Fullscreen modes, draggable panoramas, mouse scroll-to-zoom toggles, and virtual compass guides. Auto-Rotation Inactivity Delay: Automatically pause and resume rotation when a user interacts with the viewer. Premium Video Playback: Picture-in-Picture mode, playback speed controls, and advanced video controls. Title & Author Info: Customizable context overlays displaying title and author credits. Rich Galleries: Custom grid layouts, spacing, item limits, sorting, and “Load More” button customization. Advanced Google Street View: Premium interactive settings and customized auto-rotation controls. How to Use Panorama – Quick Start Go to Panorama Viewer → Add New Panorama in your WordPress dashboard. Configure the viewer from Panorama Settings to your preference. Click the Save button. Copy the generated shortcode (below the panorama title) and paste it wherever you want the viewer to appear. Prefer the block editor? Add any of the 8 Panorama blocks directly in Gutenberg. Use Cases Real Estate Agencies: Offer virtual property tours with connected scenes and hotspots. Travel Agencies: Showcase destinations with immersive 360° views. Stores & Showrooms: Present products, cars, and interiors from every angle. Museums & Art Galleries: Let visitors explore exhibitions online. Schools: Create virtual campus tours for prospective students. What Users Say ⭐⭐⭐⭐⭐ Great even on iOS ❛❛Im Happy very happy with this Plug-in. The only one which works fine with iphone❜❜ –holmh Did you like this plugin? Dislike it? Have a feature request? Please share your feedback with us Check Out Our Other WordPress Plugins 🔥 Html5 Audio Player – Best audio player plugin for WordPress. 🔥 Html5 Video Player – Best video player plugin for WordPress. 🔥 PDF Poster – A fully-featured PDF Viewer Plugin for WordPress. 🔥 StreamCast – A fully-featured Radio Player Plugin for WordPress. 🔥 3D Viewer – Display interactive 3D models on the webs. Source Code You can find the source code, report bugs, and contribute to the development of this plugin on our GitHub repository: Panorama on GitHub Third-Party Libraries This plugin bundles the following third-party JavaScript/PHP libraries. Codestar Framework Source: http://codestarframework.com/ GitHub: https://github.com/Codestar/codestar-framework License: GPLv2 or later – https://github.com/Codestar/codestar-framework/blob/master/LICENSE.md Purpose: Provides the options framework for the plugin’s settings and shortcode generator. Freemius SDK Source: https://freemius.com/ GitHub: https://github.com/Freemius/wordpress-sdk License: GPLv3 – https://github.com/Freemius/wordpress-sdk/blob/master/LICENSE.txt Purpose: Provides opt-in usage tracking and analytics to help improve the plugin. bpl-tools Source / GitHub: https://github.com/bPlugins/bpl-tools License: GPL-2.0-or-later – https://www.gnu.org/licenses/gpl-2.0.html Purpose: Shared utility library providing admin dashboard components and common Gutenberg editor controls. External Services: The library may connect to bPlugins, WordPress.org, and Freemius services for product data and checkout functionality. See full details: https://github.com/bPlugins/bpl-tools#external-requests–why-they-are-made
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C