CVE-2025-12005

WP VR – 360 Panorama and Free Virtual Tour Builder For WordPress <= 8.5.41 - Improper Authorization to Authenticated (Contributor+) Plugin Settings Update

The WP VR – 360 Panorama and Free Virtual Tour Builder For WordPress plugin for WordPress is vulnerable to unauthorized access of data in all versions up to, and including, 8.5.41. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor level access and above, to modify sensitive plugin options.


We have discovered 3,961 live websites that are affected by CVE-2025-12005.

Run a Free Instant Scan




Affected Software

Product  WPVR
Category Wordpress Plugins
Vulnerable Domains3,961 live websites (93% of WPVR install base)
Vulnerable Versions
  • from 0 through 8.5.41
Vulnerable Versions Count105 versions ( 97% of all versions)


Common Weakness Enumeration

CWE-285 Improper Authorization



Details

  • Published - Oct 25, 2025
  • Updated - Oct 27, 2025

Credits

  • Rafshanzani Suhada (finder)

Website Distribution by Country

Number of websites using CVE-2025-12005
United States681 websites



Germany701 websites
Japan693 websites
Italy205 websites
GB156 websites
France153 websites
Netherlands113 websites
Spain100 websites
Brazil83 websites
Poland77 websites

Website Distribution by TLD

Number of websites using CVE-2025-12005
.com1,433 websites
.de503 websites
.jp187 websites
.it134 websites
.net132 websites
.co.jp115 websites
.org106 websites
.co.uk96 websites
.nl94 websites
.com.br77 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-12005

Top websites that are affected by CVE-2025-12005. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****.****.gov United States**,***
***************.de Germany**,***
********.****.nl Netherlands**,***
******.edu United States***,***
*************.ca Canada***,***
****.org Spain***,***
*****.**.jp Japan***,***
***********.com United States***,***
**********.***.***.au Australia***,***
***.******.edu United States***,***
See full domain list

FAQ

CVE-2025-12005 is Improper Authorization in WPVR
A total of 3,961 websites have been identified as vulnerable to CVE-2025-12005, based on global website indexing conducted by WebTechSurvey.
The WPVR is affected by the CVE-2025-12005 vulnerability.
WPVR versions up to and including 8.5.41 are vulnerable to CVE-2025-12005.