cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches for3d-viewer 3d-viewer

Direction: ascending
Jun 07, 2024

3D viewer – Embed 3D Models on WordPress # 79871b5951fba7123eed7a0d39ed18b201b7c3b2

Date
Feb 28, 2022
Research Description
3D Viewer &#8211; WP 3D Model Viewer Plugin [3d-viewer] < 1.3.4 WordPress 3D viewer – Embed 3D Models plugin <= 1.2.6 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress 3D viewer – Embed 3D Models plugin (versions <= 1.2.6).
Affected versions
max 1.3.4.
Status
vulnerable
Oct 20, 2024

3D viewer &#8211; Embed 3D Models on WordPress # CVE-2022-4974

CVE, Research URL

CVE-2022-4974

Date
Oct 16, 2024
Research Description
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
Affected versions
max 1.2.7.
Status
vulnerable
Apr 17, 2026

3D viewer &#8211; Embed 3D Models on WordPress # CVE-2026-40729

CVE, Research URL

CVE-2026-40729

Date
Apr 15, 2026
Research Description
Missing Authorization vulnerability in bPlugins 3D viewer – Embed 3D Models 3d-viewer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 3D viewer – Embed 3D Models: from n/a through <= 1.8.5.
Affected versions
max 1.8.6.
Status
vulnerable