The WP VR plugin for WordPress has a security issue that allows attackers to inject harmful code into pages. This can happen because the plugin does not properly clean up user input and output. This vulnerability affects versions 8.5.14 and below. Attackers who have contributor-level access or higher can exploit this vulnerability to execute malicious scripts whenever a user visits a page with the injected code.