
Verge3D Publishing and E-Commerce Security & Risk Analysis
wordpress.org/plugins/verge3dVerge3D application publising and e-commerce plugin for WordPress.
Is Verge3D Publishing and E-Commerce Safe to Use in 2026?
Generally Safe
Score 94/100Verge3D Publishing and E-Commerce has a strong security track record. Known vulnerabilities have been patched promptly.
The Verge3D plugin v4.11.0 presents a mixed security posture. While it demonstrates strengths such as 100% use of prepared statements for SQL queries and a high percentage of properly escaped output, significant concerns remain. The plugin has a substantial attack surface with 17 entry points, of which 10 lack authentication or capability checks, including 4 AJAX handlers and all 6 REST API routes. This widespread lack of authorization is a critical weakness. Furthermore, taint analysis reveals one critical severity flow with unsanitized paths, indicating a potential for severe vulnerabilities like Remote Code Execution if not properly handled. The vulnerability history is also concerning, with 6 known CVEs, including one high-severity vulnerability, indicating a pattern of past security issues. Although there are currently no unpatched vulnerabilities, the historical types of vulnerabilities (Missing Authorization, CSRF, XSS, Unrestricted Upload) align with the observed weaknesses in the static analysis.
Key Concerns
- 4 AJAX handlers without auth checks
- 6 REST API routes without permission callbacks
- 1 critical severity taint flow
- 11 flows with unsanitized paths
- 1 high severity known CVE
- 5 medium severity known CVEs
- 4 dangerous functions used
Verge3D Publishing and E-Commerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
6 total CVEs
Verge3D <= 4.9.4 - Missing Authorization
Verge3D <= 4.9.3 - Reflected Cross-Site Scripting
Verge3D <= 4.9.0 - Cross-Site Request Forgery
Verge3D <= 4.8.2 - Cross-Site Request Forgery
Verge3D <= 4.8.0 - Reflected Cross-Site Scripting
Verge3D <= 4.5.2 - Authenticated(Subscriber+) Arbitrary File Upload
Verge3D Publishing and E-Commerce Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
Verge3D Publishing and E-Commerce Attack Surface
AJAX Handlers 9
REST API Routes 6
Shortcodes 2
WordPress Hooks 29
Maintenance & Trust
Verge3D Publishing and E-Commerce Maintenance & Trust
Maintenance Signals
Community Trust
Verge3D Publishing and E-Commerce Alternatives
ThreeWP
threewp
Easily integrate Three.js with WordPress to create and display 3D models and animations.
CubeLaunch
cubelaunch
Embed interactive, rotatable, pinch and zoom 3D cubes or pyramids with custom faces via Gutenberg blocks, shortcodes, or a site-wide Coming Soon page.
rooom 3D Product Viewer
rooom-3d-product-viewer
The rooom extension is a powerful tool that allows you to integrate the rooom 3D Product Viewer quickly & easily into your product pages.
WalkTheWeb
walktheweb
WalkTheWeb provides a Metaverse 3D Store front-end for your WooCommerce store in less than 5 minutes, to give you more Internet traffic and sales!
Step Kit OS
step-kit-os
A powerful WooCommerce plugin that enables 3D product customization and strengthens the connection with customers.
Verge3D Publishing and E-Commerce Developer Profile
1 plugin · 500 total installs
How We Detect Verge3D Publishing and E-Commerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/verge3d/admin/css/admin.css/wp-content/plugins/verge3d/admin/js/admin.js/wp-content/plugins/verge3d/public/css/verge3d.css/wp-content/plugins/verge3d/public/js/verge3d.js/wp-content/plugins/verge3d/admin/js/admin.js/wp-content/plugins/verge3d/public/js/verge3d.jsverge3d/admin/css/admin.css?ver=verge3d/admin/js/admin.js?ver=verge3d/public/css/verge3d.css?ver=verge3d/public/js/verge3d.js?ver=HTML / DOM Fingerprints
verge3d-containerverge3d-controlsverge3d-preloader<!-- Verge3D Application Start --><!-- Verge3D Application End --><!-- Verge3D Shortcode -->data-v3d-appdata-v3d-configv3d_plugins_urlv3d_app_dataVerge3D/wp-json/verge3d/v1/app/wp-json/verge3d/v1/order/wp-json/verge3d/v1/product[verge3d_app][verge3d_product]