plugin

Verge3D Vulnerabilities

13 known security issues reported for the Verge3D WordPress plugin. Most recent disclosed Jun 6, 2025.

1 high 5 medium

Running Verge3D on your site? Check whether your installed version is affected.

Scan your site free

Verge3D Publishing and E-Commerce [verge3d] < 4.9.5

unknown

[en] Missing Authorization vulnerability in Soft8Soft LLC Verge3D allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Verge3D: from n/a through 4.9.4.

Affected:
up to 4.9.5
Fixed in:
4.9.5
Disclosed:
Jun 6, 2025

CVE-2025-49268 on NVD →

Verge3D <= 4.9.4 - Missing Authorization

medium

The Verge3D Publishing and E-Commerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.9.4. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 4.9.4
Fixed in:
4.9.5
Disclosed:
Jun 5, 2025

CVE-2025-49268 on NVD →

Verge3D <= 4.9.3 - Reflected Cross-Site Scripting

medium

The Verge3D Publishing and E-Commerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 4.9.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if...

CVSS:
6.1
Affected:
up to 4.9.3
Fixed in:
4.9.4
Disclosed:
May 29, 2025

CVE-2025-48241 on NVD →

Verge3D Publishing and E-Commerce [verge3d] < 4.9.4

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Soft8Soft LLC Verge3D allows Reflected XSS. This issue affects Verge3D: from n/a through 4.9.3.

Affected:
up to 4.9.4
Fixed in:
4.9.4
Disclosed:
May 23, 2025

CVE-2025-48241 on NVD →

Verge3D <= 4.9.0 - Cross-Site Request Forgery

medium

The Verge3D Publishing and E-Commerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.9.0. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action granted they can...

CVSS:
4.3
Affected:
up to 4.9.0
Fixed in:
4.9.3
Disclosed:
Apr 17, 2025

CVE-2025-39443 on NVD →

Verge3D Publishing and E-Commerce [verge3d] < 4.9.3

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Soft8Soft LLC Verge3D allows Cross Site Request Forgery. This issue affects Verge3D: from n/a through 4.9.0.

Affected:
up to 4.9.3
Fixed in:
4.9.3
Disclosed:
Apr 17, 2025

CVE-2025-39443 on NVD →

Verge3D <= 4.8.2 - Cross-Site Request Forgery

medium

The Verge3D Publishing and E-Commerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.8.2. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action granted they can...

CVSS:
4.3
Affected:
up to 4.8.2
Fixed in:
4.8.3
Disclosed:
Mar 27, 2025

CVE-2025-30833 on NVD →

Verge3D Publishing and E-Commerce [verge3d] < 4.8.3

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Soft8Soft LLC Verge3D allows Cross Site Request Forgery. This issue affects Verge3D: from n/a through 4.8.2.

Affected:
up to 4.8.3
Fixed in:
4.8.3
Disclosed:
Mar 27, 2025

CVE-2025-30833 on NVD →

Verge3D Publishing and E-Commerce [verge3d] < 4.8.1

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Soft8Soft LLC Verge3D allows Reflected XSS. This issue affects Verge3D: from n/a through 4.8.0.

Affected:
up to 4.8.1
Fixed in:
4.8.1
Disclosed:
Jan 21, 2025

CVE-2025-22709 on NVD →

Verge3D <= 4.8.0 - Reflected Cross-Site Scripting

medium

The Verge3D plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.8.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a...

CVSS:
6.1
Affected:
up to 4.8.0
Fixed in:
4.8.1
Disclosed:
Jan 15, 2025

CVE-2025-22709 on NVD →

Verge3D Publishing and E-Commerce [verge3d] < 4.5.3

unknown

[en] Improper Control of Generation of Code ('Code Injection') vulnerability in Soft8Soft LLC Verge3D Publishing and E-Commerce.This issue affects Verge3D Publishing and E-Commerce: from n/a through 4.5.2.

Affected:
up to 4.5.3
Fixed in:
4.5.3
Disclosed:
Dec 29, 2023

CVE-2023-51420 on NVD →

Verge3D Publishing and E-Commerce [verge3d] < 4.5.3

unknown

[en] Unrestricted Upload of File with Dangerous Type vulnerability in Soft8Soft LLC Verge3D Publishing and E-Commerce.This issue affects Verge3D Publishing and E-Commerce: from n/a through 4.5.2.

Affected:
up to 4.5.3
Fixed in:
4.5.3
Disclosed:
Dec 29, 2023

CVE-2023-51421 on NVD →

Verge3D <= 4.5.2 - Authenticated(Subscriber+) Arbitrary File Upload

high

The Verge3D Publishing and E-Commerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'v3d_upload_app_file' function in all versions up to, and including, 4.5.2. This makes it possible for authenticated attackers, with subscriber access and above, to upload arbitr...

CVSS:
8.8
Affected:
up to 4.5.2
Fixed in:
4.5.3
Disclosed:
Dec 27, 2023

CVE-2023-51421 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database