Ipanorama 360 is a WordPress virtual-tour-builder plugin that enables interactive panoramic content creation and presentation within WordPress sites. The observed vulnerability exposure centers on SQL-injection weaknesses in the plugin's database-query handling, a pattern characteristic of web-application input-validation issues in content-management extensions. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ipanorama 360 Wordpress Virtual Tour Builder Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-5336MEDIUM The iPanorama 360 – WordPress Virtual Tour Builder plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 1.8.0 due to ins | Oct 19, 2023 | 6.5 | 20 | NO | NO |
CVE-2022-4392MEDIUM The iPanorama 360 WordPress Virtual Tour Builder plugin through 1.6.29 does not sanitise and escape some of its settings, which could allow users such as contributor+ to perform St | Jan 9, 2023 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ipanorama 360 Wordpress Virtual Tour Builder Project.
Media articles that mention a CVE ID that affects a product developed by Ipanorama 360 Wordpress Virtual Tour Builder Project — matched by CVE ID, not by vendor name.