WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in AR for WordPress

Augmented Reality for WordPress lets you showcase 3D models in an interactive viewer and AR on iOS and Android, with no app downloads needed.

5Reported vulnerabilities
10Highest CVSS score
8.45Latest version
300+Active installs

What to do now

Update AR for WordPress to 8.41 or later. 5 of these have a fixed version available. Updating resolves them.

Plugin last updated: August 13, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2024-50496 Critical 10 0.5% 7.0 and earlier 7.0 October 28, 2024
CVE-2025-60156 Critical 9.6 0.2% 0 to 8.34 (inclusive) 8.45 September 26, 2025
CVE-2026-14327 High 7.5 0.6% 0 to 8.40 (inclusive) 8.41 July 3, 2026
CVE-2025-26913 Medium 6.5 0.3% 0 to 7.7 (inclusive) 7.8 February 25, 2025
CVE-2024-12300 Low 3.7 0.4% 0 to 7.3 (inclusive) 7.4 December 13, 2024

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.