The WP VR – 360 Panorama and Free Virtual Tour Builder For WordPress plugin for WordPress has a security issue that allows attackers to insert harmful code into web pages. This can happen when a user with Contributor-level access or higher adds a ‘hotspot-hover’ parameter. The vulnerability affects all versions up to and including 8.5.32, as the plugin does not properly check and clean the input and output.