plugin

Ipanorama 360 Virtual Tour Builder Lite Vulnerabilities

16 known security issues reported for the Ipanorama 360 Virtual Tour Builder Lite WordPress plugin. Most recent disclosed Nov 1, 2024.

2 high 4 medium

Running Ipanorama 360 Virtual Tour Builder Lite on your site? Check whether your installed version is affected.

Scan your site free

iPanorama 360 &#8211; Advanced Virtual Tour Builder [ipanorama-360-virtual-tour-builder-lite] < 1.8.4

unknown

[en] Missing Authorization vulnerability in Avirtum iPanorama 360 WordPress Virtual Tour Builder allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects iPanorama 360 WordPress Virtual Tour Builder: from n/a through 1.8.3.

Affected:
up to 1.8.4
Fixed in:
1.8.4
Disclosed:
Nov 1, 2024

CVE-2024-38690 on NVD →

iPanorama 360 WordPress Virtual Tour Builder <= 1.8.3 - Missing Authorization

medium

The iPanorama 360 WordPress Virtual Tour Builder plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the do_parse_request() function in versions up to, and including, 1.8.3. This makes it possible for unauthenticated attackers to preview deactivated panoramas.

CVSS:
5.3
Affected:
up to 1.8.3
Fixed in:
1.8.4
Disclosed:
Jul 10, 2024

CVE-2024-38690 on NVD →

iPanorama 360 &#8211; Advanced Virtual Tour Builder [ipanorama-360-virtual-tour-builder-lite] < 1.8.2

unknown

[en] Missing Authorization vulnerability in Avirtum iPanorama 360 WordPress Virtual Tour Builder.This issue affects iPanorama 360 WordPress Virtual Tour Builder: from n/a through 1.8.1.

Affected:
up to 1.8.2
Fixed in:
1.8.2
Disclosed:
May 3, 2024

CVE-2024-33941 on NVD →

iPanorama 360 WordPress Virtual Tour Builder <= 1.8.1 - Missing Authorization

medium

The iPanorama 360 WordPress Virtual Tour Builder plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on a REST API endpoint in versions up to, and including, 1.8.1. This makes it possible for unauthenticated attackers to view deactivated panoramas.

CVSS:
5.3
Affected:
up to 1.8.1
Fixed in:
1.8.2
Disclosed:
Apr 30, 2024

CVE-2024-33941 on NVD →

iPanorama 360 &#8211; Advanced Virtual Tour Builder [ipanorama-360-virtual-tour-builder-lite] < 1.8.1

unknown

[en] The iPanorama 360 – WordPress Virtual Tour Builder plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 1.8.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible...

Affected:
up to 1.8.1
Fixed in:
1.8.1
Disclosed:
Oct 19, 2023

CVE-2023-5336 on NVD →

iPanorama 360 – WordPress Virtual Tour Builder <= 1.8.0 - Authenticated (Contributor+) SQL Injection via Shortcode

high

The iPanorama 360 – WordPress Virtual Tour Builder plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 1.8.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for a...

CVSS:
8.8
Affected:
up to 1.8.0
Fixed in:
1.8.1
Disclosed:
Oct 18, 2023

CVE-2023-5336 on NVD →

iPanorama 360 &#8211; Advanced Virtual Tour Builder [ipanorama-360-virtual-tour-builder-lite] < 1.8.0

unknown

Update the WordPress iPanorama 360 WordPress Virtual Tour Builder plugin to the latest available version (at least 1.8.0). Unknown discovered and reported this SQL Injection vulnerability in WordPress iPanorama 360 WordPress Virtual Tour Builder Plugin. This could allow a malicious actor to directly interact with your...

Affected:
up to 1.8.0
Fixed in:
1.8.0
Disclosed:
Sep 25, 2023

iPanorama 360 – WordPress Virtual Tour Builder <= 1.7.3 - Authenticated (Admin+) SQL injection

high

The iPanorama 360 plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in versions up to, and including, 1.7.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with ad...

CVSS:
7.2
Affected:
up to 1.8.0
Fixed in:
1.8.0
Disclosed:
Sep 22, 2023

iPanorama 360 &#8211; Advanced Virtual Tour Builder [ipanorama-360-virtual-tour-builder-lite] < 1.8.0

unknown

The iPanorama 360 plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in versions up to, and including, 1.7.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with ad...

Affected:
up to 1.8.0
Fixed in:
1.8.0
Disclosed:
Sep 22, 2023

iPanorama 360 &#8211; Advanced Virtual Tour Builder [ipanorama-360-virtual-tour-builder-lite] < 1.6.30

unknown

[en] The iPanorama 360 WordPress Virtual Tour Builder plugin through 1.6.29 does not sanitise and escape some of its settings, which could allow users such as contributor+ to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

Affected:
up to 1.6.30
Fixed in:
1.6.30
Disclosed:
Jan 9, 2023

CVE-2022-4392 on NVD →

iPanorama 360 WordPress Virtual Tour Builder <= 1.6.29 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The iPanorama 360 WordPress Virtual Tour Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in versions up to, and including, 1.6.29 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor level per...

CVSS:
6.4
Affected:
up to 1.6.29
Fixed in:
1.6.30
Disclosed:
Dec 16, 2022

CVE-2022-4392 on NVD →

iPanorama 360 WordPress Virtual Tour Builder < 1.6.22 - Reflected Cross-Site Scripting

medium

The iPanorama 360 WordPress Virtual Tour Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in versions before 1.6.22 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pag...

CVSS:
6.1
Affected:
up to 1.6.22
Fixed in:
1.6.22
Disclosed:
Oct 11, 2021

iPanorama 360 &#8211; Advanced Virtual Tour Builder [ipanorama-360-virtual-tour-builder-lite] < 1.6.22

unknown

Reflected Cross-Site Scripting (XSS) vulnerability discovered by WPScanTeam in WordPress Download iPanorama 360 WordPress Virtual Tour Builder plugin (versions <= 1.6.21).

Affected:
up to 1.6.22
Fixed in:
1.6.22
Disclosed:
Oct 11, 2021

iPanorama 360 &#8211; Advanced Virtual Tour Builder [ipanorama-360-virtual-tour-builder-lite] < 1.6.22

unknown

The iPanorama 360 WordPress Virtual Tour Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in versions before 1.6.22 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pag...

Affected:
up to 1.6.22
Fixed in:
1.6.22
Disclosed:
Oct 11, 2021

iPanorama 360 &#8211; Advanced Virtual Tour Builder [ipanorama-360-virtual-tour-builder-lite] < 1.6.22

unknown

Most plugins (both free and premium) from the Avirtum author do not escape a page parameter before outputting it back in attributes, leading to Reflected Cross-Site Scripting issues. The issues were reported to the vendor on August 4th, 2021

Affected:
up to 1.6.22
Fixed in:
1.6.22

iPanorama 360 &#8211; Advanced Virtual Tour Builder [ipanorama-360-virtual-tour-builder-lite] < 1.8.0

unknown

The iPanorama 360 plugin for WordPress is vulnerable to SQL Injection via the &#039;orderby&#039; parameter in versions up to, and including, 1.7.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers...

Affected:
up to 1.8.0
Fixed in:
1.8.0

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database