Known Vulnerabilities for products from Rextheme

Listed below are 4 of the newest known vulnerabilities associated with the vendor "Rextheme".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2025-62885 json Not Provided 2025-10-27 2026-04-01
CVE-2025-47452 json Not Provided 2025-06-17 2026-04-23
CVE-2025-24730 json Not Provided 2025-01-24 2026-04-23
CVE-2024-49680 json Not Provided 2024-11-19 2026-04-23
CVE-2024-49293 json Missing Authorization vulnerability in RexTheme WP VR wpvr allows Exploiting Incorrectly Configured Access Control Security L... Not Provided 2024-10-21 2026-04-23
CVE-2023-40663 json Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Rextheme WP VR plugin <= 8.3.4 versions. 6.1 - MEDIUM 2023-09-27 2023-09-28
CVE-2023-0174 json The WP VR WordPress plugin before 8.2.7 does not validate and escape some of its shortcode attributes before outputting them ... 5.4 - MEDIUM 2023-02-06 2023-11-07
CVE-2022-47449 json Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in RexTheme Cart Lift – Abandoned Cart Recovery for WooCommerce ... 6.1 - MEDIUM 2023-05-04 2023-05-10