iPanorama 360 – Advanced Virtual Tour Builder [ipanorama-360-virtual-tour-builder-lite] < 1.8.4
unknown
[en] Missing Authorization vulnerability in Avirtum iPanorama 360 WordPress Virtual Tour Builder allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects iPanorama 360 WordPress Virtual Tour Builder: from n/a through 1.8.3.
- Affected:
- up to 1.8.4
- Fixed in:
- 1.8.4
- Disclosed:
- Nov 1, 2024
CVE-2024-38690 on NVD →
iPanorama 360 WordPress Virtual Tour Builder <= 1.8.3 - Missing Authorization
medium
The iPanorama 360 WordPress Virtual Tour Builder plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the do_parse_request() function in versions up to, and including, 1.8.3. This makes it possible for unauthenticated attackers to preview deactivated panoramas.
- CVSS:
- 5.3
- Affected:
- up to 1.8.3
- Fixed in:
- 1.8.4
- Disclosed:
- Jul 10, 2024
CVE-2024-38690 on NVD →
iPanorama 360 – Advanced Virtual Tour Builder [ipanorama-360-virtual-tour-builder-lite] < 1.8.2
unknown
[en] Missing Authorization vulnerability in Avirtum iPanorama 360 WordPress Virtual Tour Builder.This issue affects iPanorama 360 WordPress Virtual Tour Builder: from n/a through 1.8.1.
- Affected:
- up to 1.8.2
- Fixed in:
- 1.8.2
- Disclosed:
- May 3, 2024
CVE-2024-33941 on NVD →
iPanorama 360 WordPress Virtual Tour Builder <= 1.8.1 - Missing Authorization
medium
The iPanorama 360 WordPress Virtual Tour Builder plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on a REST API endpoint in versions up to, and including, 1.8.1. This makes it possible for unauthenticated attackers to view deactivated panoramas.
- CVSS:
- 5.3
- Affected:
- up to 1.8.1
- Fixed in:
- 1.8.2
- Disclosed:
- Apr 30, 2024
CVE-2024-33941 on NVD →
iPanorama 360 – Advanced Virtual Tour Builder [ipanorama-360-virtual-tour-builder-lite] < 1.8.1
unknown
[en] The iPanorama 360 – WordPress Virtual Tour Builder plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 1.8.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible...
- Affected:
- up to 1.8.1
- Fixed in:
- 1.8.1
- Disclosed:
- Oct 19, 2023
CVE-2023-5336 on NVD →
iPanorama 360 – WordPress Virtual Tour Builder <= 1.8.0 - Authenticated (Contributor+) SQL Injection via Shortcode
high
The iPanorama 360 – WordPress Virtual Tour Builder plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 1.8.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for a...
- CVSS:
- 8.8
- Affected:
- up to 1.8.0
- Fixed in:
- 1.8.1
- Disclosed:
- Oct 18, 2023
CVE-2023-5336 on NVD →
iPanorama 360 – Advanced Virtual Tour Builder [ipanorama-360-virtual-tour-builder-lite] < 1.8.0
unknown
Update the WordPress iPanorama 360 WordPress Virtual Tour Builder plugin to the latest available version (at least 1.8.0).
Unknown discovered and reported this SQL Injection vulnerability in WordPress iPanorama 360 WordPress Virtual Tour Builder Plugin. This could allow a malicious actor to directly interact with your...
- Affected:
- up to 1.8.0
- Fixed in:
- 1.8.0
- Disclosed:
- Sep 25, 2023
iPanorama 360 – WordPress Virtual Tour Builder <= 1.7.3 - Authenticated (Admin+) SQL injection
high
The iPanorama 360 plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in versions up to, and including, 1.7.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with ad...
- CVSS:
- 7.2
- Affected:
- up to 1.8.0
- Fixed in:
- 1.8.0
- Disclosed:
- Sep 22, 2023
iPanorama 360 – Advanced Virtual Tour Builder [ipanorama-360-virtual-tour-builder-lite] < 1.8.0
unknown
The iPanorama 360 plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in versions up to, and including, 1.7.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with ad...
- Affected:
- up to 1.8.0
- Fixed in:
- 1.8.0
- Disclosed:
- Sep 22, 2023
iPanorama 360 – Advanced Virtual Tour Builder [ipanorama-360-virtual-tour-builder-lite] < 1.6.30
unknown
[en] The iPanorama 360 WordPress Virtual Tour Builder plugin through 1.6.29 does not sanitise and escape some of its settings, which could allow users such as contributor+ to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
- Affected:
- up to 1.6.30
- Fixed in:
- 1.6.30
- Disclosed:
- Jan 9, 2023
CVE-2022-4392 on NVD →
iPanorama 360 WordPress Virtual Tour Builder <= 1.6.29 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The iPanorama 360 WordPress Virtual Tour Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in versions up to, and including, 1.6.29 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor level per...
- CVSS:
- 6.4
- Affected:
- up to 1.6.29
- Fixed in:
- 1.6.30
- Disclosed:
- Dec 16, 2022
CVE-2022-4392 on NVD →
iPanorama 360 WordPress Virtual Tour Builder < 1.6.22 - Reflected Cross-Site Scripting
medium
The iPanorama 360 WordPress Virtual Tour Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in versions before 1.6.22 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pag...
- CVSS:
- 6.1
- Affected:
- up to 1.6.22
- Fixed in:
- 1.6.22
- Disclosed:
- Oct 11, 2021
iPanorama 360 – Advanced Virtual Tour Builder [ipanorama-360-virtual-tour-builder-lite] < 1.6.22
unknown
Reflected Cross-Site Scripting (XSS) vulnerability discovered by WPScanTeam in WordPress Download iPanorama 360 WordPress Virtual Tour Builder plugin (versions <= 1.6.21).
- Affected:
- up to 1.6.22
- Fixed in:
- 1.6.22
- Disclosed:
- Oct 11, 2021
iPanorama 360 – Advanced Virtual Tour Builder [ipanorama-360-virtual-tour-builder-lite] < 1.6.22
unknown
The iPanorama 360 WordPress Virtual Tour Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in versions before 1.6.22 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pag...
- Affected:
- up to 1.6.22
- Fixed in:
- 1.6.22
- Disclosed:
- Oct 11, 2021
iPanorama 360 – Advanced Virtual Tour Builder [ipanorama-360-virtual-tour-builder-lite] < 1.6.22
unknown
Most plugins (both free and premium) from the Avirtum author do not escape a page parameter before outputting it back in attributes, leading to Reflected Cross-Site Scripting issues.
The issues were reported to the vendor on August 4th, 2021
- Affected:
- up to 1.6.22
- Fixed in:
- 1.6.22
iPanorama 360 – Advanced Virtual Tour Builder [ipanorama-360-virtual-tour-builder-lite] < 1.8.0
unknown
The iPanorama 360 plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in versions up to, and including, 1.7.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers...
- Affected:
- up to 1.8.0
- Fixed in:
- 1.8.0
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database