Vulnerabilities and security researches for3d-viewer 3d-viewer
Direction: descendingApr 17, 2026
3D viewer – Embed 3D Models on WordPress # CVE-2026-40729
- CVE, Research URL
- Application
- Date
- Apr 15, 2026
- Research Description
- Missing Authorization vulnerability in bPlugins 3D viewer – Embed 3D Models 3d-viewer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 3D viewer – Embed 3D Models: from n/a through <= 1.8.5.
- Affected versions
-
max 1.8.6.
- Status
-
vulnerable
Oct 20, 2024
3D viewer – Embed 3D Models on WordPress # CVE-2022-4974
- CVE, Research URL
- Application
- Date
- Oct 16, 2024
- Research Description
- The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
- Affected versions
-
max 1.2.7.
- Status
-
vulnerable
Jun 07, 2024
3D viewer – Embed 3D Models on WordPress # 79871b5951fba7123eed7a0d39ed18b201b7c3b2
- CVE, Research URL
- Application
- Date
- Feb 28, 2022
- Research Description
- 3D Viewer – WP 3D Model Viewer Plugin [3d-viewer] < 1.3.4 WordPress 3D viewer – Embed 3D Models plugin <= 1.2.6 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress 3D viewer – Embed 3D Models plugin (versions <= 1.2.6).
- Affected versions
-
max 1.3.4.
- Status
-
vulnerable