cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forwoo-3d-viewer woo-3d-viewer

Direction: ascending
Jul 05, 2025

Easy 3D Viewer # fb2e1bb3521d3147fbf4886d171a91edce069e89

Application

Easy 3D Viewer

Date
-
Research Description
Easy 3D Viewer [woo-3d-viewer] < 1.8.6.7 Multiple Plugins &lt;= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via prettyPhoto JavaScript Library Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin&#039;s bundled prettyPhoto library (version 3.1.6) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
Min -, max -.
Status
vulnerable