The WP VR plugin for WordPress has a security issue that allows unauthorized changes to data. This is because the plugin does not have a proper check in place for the wpvr_review_request() function. This vulnerability exists in versions up to 8.5.5, which means that attackers who are logged in and have at least subscriber-level access can dismiss notices and create contacts without permission.