Medium 5.3
2025-06-06< 4.9.5
CVE-2025-49268
Minimum safe version
4.9.5
Update to 4.9.5 or later to address 7 fixable vulnerabilities
CVE-2025-49268
Verge3D <= 4.9.3 - Reflected Cross-Site Scripting
CVE-2025-39443
CVE-2025-30833
CVE-2025-22709
WordPress Verge3D Plugin <= 4.5.2 is vulnerable to Arbitrary File Upload
WordPress Verge3D Plugin <= 4.5.2 is vulnerable to Remote Code Execution (RCE)