Sceawere
Vulnerability Detail
CVE-2026-104386UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
WP VR Missing Authorization Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 10h ago
- Vendor
- WPFunnels Team
- Product
- WP VR
- Attack Type
- Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Missing Authorization vulnerability in WPFunnels Team WP VR wpvr allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP VR: from n/a through 9.1.3.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-10-05T09:17:07.380Z",
"pubdate": "2026-10-05T09:17:07.380Z",
"executiveSummary": "The WP VR plugin, developed by the WPFunnels Team, is affected by a missing authorization vulnerability.\nThis security flaw stems from an incorrectly configured access control mechanism within the application's request handling logic.\nThe vulnerability allows unauthorized users to perform actions restricted by higher privilege levels, circumventing intended security boundaries.\nAffected versions include all releases from n/a through 9.1.3.\nThe primary risk involves unauthorized access to sensitive plugin functionality or data modification, potentially leading to privilege escalation or unauthorized administrative operations.\nExploitation does not require elevated administrative privileges, making it accessible to authenticated or unauthenticated attackers depending on the specific endpoint exposure.\nSystem administrators should prioritize mitigating this risk by limiting external access to the vulnerable components and ensuring the plugin is monitored for unauthorized activity.",
"technicalDetails": "The vulnerability is rooted in an improper implementation of authorization checks within the WP VR plugin's API endpoints or administrative action handlers.\nIn WordPress plugin development, security best practices dictate that every request handler must verify the user's capabilities using functions like current_user_can() and perform nonces validation to ensure request legitimacy.\nThe flaw exists because the plugin fails to enforce these checks consistently across all exposed functional interfaces, allowing requests to proceed without validating the identity or privilege level of the requester.\nAttack flow typically begins with an actor identifying the specific endpoint associated with the plugin’s backend functionality.\nBy crafting a malicious HTTP request targeting these endpoints, an attacker can bypass the intended access control security levels.\nBecause the plugin does not verify if the requester possesses the required permissions (e.g., 'manage_options' or similar administrative capabilities), the server-side code executes the requested function under the security context of the application rather than the requester.\nThe missing authorization specifically enables an attacker to interact with backend processes that modify configuration settings, inject data, or retrieve information that should be protected from unauthorized parties.\nThe vulnerability exists within the codebase of WP VR versions up to 9.1.3, specifically affecting logic paths where authorization checks are either entirely omitted or improperly implemented for asynchronous requests.\nPost-exploitation, an attacker could potentially manipulate plugin configurations, leading to persistent cross-site scripting (XSS) via injected content, unauthorized modifications to virtual reality tour settings, or unauthorized access to plugin-stored data, depending on the scope of the affected function.\nAs this is a server-side authorization flaw, the exploit is not reliant on client-side browser interactions but rather on the direct communication between the attacker's tool and the web server's request handling engine."
}