Executive brief
The Panorama Viewer plugin for WordPress, which allows websites to display 360-degree images and videos, contains a security vulnerability that could allow an attacker to access sensitive server files. By exploiting this flaw, a user with contributor-level permissions could view internal configuration files, potentially leading to the theft of database credentials or a full site takeover. This risk is particularly high for sites that allow multiple users to contribute content.
Technical details
A Local File Inclusion (LFI) vulnerability exists in the bPlugins Panorama Viewer plugin for WordPress (versions <= 1.6.1) due to improper control of filenames in PHP 'include' or 'require' statements (CWE-98). An attacker with 'Contributor' level privileges can exploit this flaw to include and execute local files on the server. While the attack complexity is rated as high, successful exploitation could allow an attacker to read sensitive files such as wp-config.php, potentially leading to credential theft and full system compromise. The issue is resolved in version 1.7.0.
Affected products
- bPlugins Panorama Viewer – 360 Degree Image + Video Viewer <= 1.6.1
Timeline
- 2026-04-19: other: Vulnerability reported by researcher endy
- 2026-06-26: advisory: Published by Patchstack and NVD
- 2026-06-26: patched: Patch available in version 1.7.0