plugin

Press3D Vulnerabilities

1 known security issue reported for the Press3D WordPress plugin. Most recent disclosed Feb 13, 2026.

1 medium

Running Press3D on your site? Check whether your installed version is affected.

Scan your site free

Press3D <= 1.0.2 - Authenticated (Author+) Stored Cross-Site Scripting via Link URL Parameter in 3D Model Block

medium

The Press3D plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 3D Model Gutenberg block in all versions up to, and including, 1.0.2. This is due to the plugin failing to sanitize and validate the URL scheme when storing link URLs for 3D model blocks, allowing `javascript:` URLs. This makes it pos...

CVSS:
6.4
Affected:
up to 1.0.2
Fixed in:
1.1.0
Disclosed:
Feb 13, 2026

CVE-2026-1985 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database