What the vulnerability does
01Description
Missing Authorization vulnerability in bPlugins 3D viewer – Embed 3D Models 3d-viewer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 3D viewer – Embed 3D Models: from n/a through <= 1.8.5.
Explanation of Vulnerability in Simple Terms
02Summary
The 3D Viewer plugin for WordPress contains a missing authorization check that allows authenticated users with low privileges to modify content they should not have access to. An attacker with a basic user account can alter data through the plugin's functionality. The vulnerability affects versions up to 1.8.5. Update to a version newer than 1.8.5 to resolve this issue.
What an attacker can do
03Attacker Capabilities
Modify or alter content through the plugin without proper permission checks.
Potential impact on your site
04Site Impact
Unauthorized users can modify 3D model data or plugin settings, potentially corrupting content or defacing the site.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege WordPress user account (e.g., subscriber or contributor).
Key dates
06Disclosure timeline
April 15, 2026
CVE published
April 29, 2026
Record updated