20 lines
698 B
JSON
Raw Normal View History

{
"id": "CVE-2023-6529",
"sourceIdentifier": "contact@wpscan.com",
"published": "2024-01-08T19:15:10.320",
"lastModified": "2024-01-08T19:30:06.923",
"vulnStatus": "Awaiting Analysis",
"descriptions": [
{
"lang": "en",
"value": "The WP VR WordPress plugin before 8.3.15 does not authorisation and CSRF in a function hooked to admin_init, allowing unauthenticated users to downgrade the plugin, thus leading to Reflected or Stored XSS, as previous versions have such vulnerabilities."
}
],
"metrics": {},
"references": [
{
"url": "https://wpscan.com/vulnerability/c36314c1-a2c0-4816-93c9-e61f9cf7f27a",
"source": "contact@wpscan.com"
}
]
}