Rextheme develops a small set of WordPress-focused plugins and extensions, primarily Cart Lift for abandoned-cart recovery across WooCommerce and EDD storefronts, that extend e-commerce functionality in widely deployed content management systems. Its vulnerability exposure recurs through web-application weaknesses—cross-site scripting, cross-site request forgery, and missing authorization controls—that are characteristic of plugin-layer code operating within the WordPress environment. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rextheme over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-25708HIGH Cross-Site Request Forgery (CSRF) vulnerability in Rextheme WP VR – 360 Panorama and Virtual Tour Builder For WordPress plugin <= 8.2.7 versions. | Mar 15, 2023 | 8.8 | 27 | NO | NO |
CVE-2025-47452CRITICAL Unrestricted Upload of File with Dangerous Type vulnerability in RexTheme WP VR wpvr allows Upload a Web Shell to a Web Server.This issue affects WP VR: from n/a through <= 8.5.26. | Jun 17, 2025 | 9.9 | 25 | NO | NO |
CVE-2023-1413MEDIUM The WP VR WordPress plugin before 8.2.9 does not sanitise and escape some parameters before outputting them back in the page, leading to a Reflected Cross-Site Scripting which coul | Apr 17, 2023 | 6.1 | 21 | NO | NO |
CVE-2025-62885MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RexTheme WP VR wpvr allows DOM-Based XSS.This issue affects WP VR: from n/a th | Oct 27, 2025 | 6.5 | 20 | NO | NO |
CVE-2022-47449MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in RexTheme Cart Lift – Abandoned Cart Recovery for WooCommerce and EDD plugin <= 3.1.5 versions. | May 4, 2023 | 6.1 | 20 | NO | NO |
CVE-2025-24730MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RexTheme WP VR wpvr allows DOM-Based XSS.This issue affects WP VR: from n/a th | Jan 24, 2025 | 6.5 | 19 | NO | NO |
CVE-2023-6529MEDIUM The WP VR WordPress plugin before 8.3.15 does not authorisation and CSRF in a function hooked to admin_init, allowing unauthenticated users to downgrade the plugin, thus leading to | Jan 8, 2024 | 6.1 | 19 | NO | NO |
CVE-2023-40663MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Rextheme WP VR plugin <= 8.3.4 versions. | Sep 27, 2023 | 6.1 | 19 | NO | NO |
CVE-2023-0174MEDIUM The WP VR WordPress plugin before 8.2.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which | Feb 6, 2023 | 5.4 | 19 | NO | NO |
CVE-2025-6350MEDIUM The WP VR – 360 Panorama and Free Virtual Tour Builder For WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘hotspot-hover’ parameter in all vers | Jun 28, 2025 | 5.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rextheme.
Media articles that mention a CVE ID that affects a product developed by Rextheme — matched by CVE ID, not by vendor name.