VYPR

Visualizer

by WordPress

Source repositories

CVEs (17)

  • CVE-2019-16932CriSep 30, 2019
    risk 0.68cvss 10.0epss 0.39

    A blind SSRF vulnerability exists in the Visualizer plugin before 3.3.1 for WordPress via wp-json/visualizer/v1/upload-data.

  • CVE-2024-35736HigJun 8, 2024
    risk 0.55cvss 8.5epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle Visualizer.This issue affects Visualizer: from n/a through 3.11.1.

  • CVE-2024-3750HigMay 16, 2024
    risk 0.50cvss 8.8epss 0.01

    The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to unauthorized modification and retrieval of data due to a missing capability check on the getQueryData() function in all versions up to, and including, 3.10.15. This makes it possible…

  • CVE-2024-27958HigMar 17, 2024
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeisle Visualizer allows Reflected XSS.This issue affects Visualizer: from n/a through 3.10.5.

  • CVE-2026-86784MedSep 16, 2026
    risk 0.44cvss 6.8epss 0.00

    The Visualizer WordPress plugin before 4.0.8 does not sanitise and escape a chart's JSON data source configuration before outputting it back in the chart editor, allowing users with the Contributor role and above to store JavaScript that executes in the browser of any…

  • CVE-2026-14939MedAug 4, 2026
    risk 0.44cvss 6.8epss 0.00

    The Visualizer WordPress plugin before 4.0.6 does not restrict a user-supplied URL to safe address ranges before fetching it server-side, allowing users with Contributor-level access and above to perform Server-Side Request Forgery against link-local instance-metadata…

  • CVE-2026-19726MedAug 16, 2026
    risk 0.42cvss 6.5epss 0.00

    The Visualizer WordPress plugin before 4.0.7 does not properly authorise access to the configuration of its charts, allowing users with the Contributor role and above to read the full configuration of any chart on the site, including charts the Visualizer WordPress plugin…

  • CVE-2025-12483MedDec 2, 2025
    risk 0.42cvss 6.5epss 0.00

    The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'query' parameter in all versions up to, and including, 3.11.12 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on…

  • CVE-2019-16931MedOct 3, 2019
    risk 0.40cvss 6.1epss 0.03

    A stored XSS vulnerability in the Visualizer plugin 3.3.0 for WordPress allows an unauthenticated attacker to execute arbitrary JavaScript when an admin or other privileged user edits the chart via the admin dashboard. This occurs because classes/Visualizer/Gutenberg/Block.php…

  • CVE-2026-86782MedSep 11, 2026
    risk 0.36cvss 5.5epss 0.00

    The Visualizer WordPress plugin before 4.0.6 does not properly authorise access to its chart-building actions, allowing users with the Contributor role and above to publish, rename, and overwrite the content of posts and pages they do not own, including other users' private…

  • CVE-2026-24573MedMay 20, 2026
    risk 0.35cvss 6.5epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeisle Visualizer allows Stored XSS. This issue affects Visualizer: from n/a before 4.0.0.

  • CVE-2025-1065MedFeb 19, 2025
    risk 0.35cvss 6.4epss 0.00

    The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Import Data From File feature in all versions up to, and including, 3.11.8 due to insufficient input sanitization and output escaping on…

  • CVE-2026-8689MedMay 28, 2026
    risk 0.21cvss 4.3epss 0.00

    The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.11.14. This is due to a missing capability check on the renderChartPages() and uploadData() functions, where the…

  • CVE-2026-86779LowSep 11, 2026
    risk 0.18cvss 2.7epss 0.00

    The Visualizer WordPress plugin before 4.0.6 does not properly authorise chart-deletion requests, performing only a site-wide capability check with no per-object ownership verification, allowing users with the Contributor role and above to permanently delete any chart on the…

  • CVE-2026-15653MedJul 24, 2026
    risk 0.00cvss 6.4epss 0.00

    The Visualizer – Tables & Charts Manager with Built-in AI Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'backend-title' parameter in all versions up to, and including, 4.0.5 due to insufficient input sanitization and output escaping. This…

  • CVE-2026-65526HigJul 23, 2026
    risk 0.00cvss 8.5epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle Visualizer allows Blind SQL Injection. This issue affects Visualizer: from n/a through 4.0.1.

  • CVE-2026-13468HigJul 1, 2026
    risk 0.00cvss 7.5epss 0.01

    The Visualizer – Tables & Charts Manager with Built-in AI Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This…