The WP VR plugin for WordPress has a security issue that allows unauthorized access. This is because the plugin does not check for the appropriate permissions on a certain function in versions 8.5.4 and earlier. This means that attackers who are logged in with contributor-level access or higher can perform actions that they are not supposed to.