WP VR – 360 Panorama and Free Virtual Tour Builder For WordPress <= 8.5.41 - Improper Authorization to Authenticated (Contributor+) Plugin Settings Update

2025-10-24 16:51
Rafshanzani Suhada

Strategic Overview

Status
Patched in 8.5.42
Affected Version<= 8.5.41
CVSS4.3Medium
CVECVE-2025-12005
View all WP VR – 360 Panorama and Virtual Tour Builder vulnerabilities

Vulnerability Overview

The WP VR – 360 Panorama and Free Virtual Tour Builder For WordPress plugin for WordPress is vulnerable to unauthorized access of data in all versions up to, and including, 8.5.41. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor level access and above, to modify sensitive plugin options.

Technical Analysis

REMEDIATION: Update to version 8.5.42, or a newer patched version --- IDENTIFIER: CWE-285 (Improper Authorization) The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C