The 3D Viewer – 3D Model Viewer – Augmented Reality – Virtual Try On plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.0.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify all plugin settings by writing arbitrary data to the ar_try_on_settings option in the database via the /wp-json/ar_try_on/v1/settings REST endpoint.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 28 May 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 28 May 2026 07:30:00 +0000
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-05-28T10:33:38.952Z
Reserved: 2026-05-15T13:40:00.628Z
Link: CVE-2026-8682
Updated: 2026-05-28T10:33:33.353Z
Status : Deferred
Published: 2026-05-28T08:16:37.590
Modified: 2026-05-28T13:45:25.260
Link: CVE-2026-8682
No data.
OpenCVE Enrichment
Updated: 2026-05-28T08:30:12Z
Weaknesses