WordPress Visualizer Plugin <= 3.9.1 is vulnerable to Cross Site Scripting (XSS)
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6.5epss 0.5%
exploitation probability
0.5%top 59% of all CVEs
observed exploitation
nono source reports it
In short
The WordPress Visualizer plugin version 3.9.1 and earlier allows authenticated users with contributor privileges to inject malicious scripts that get stored and executed in other users' browsers. This can compromise site security and user data.
Technical detail
Authenticated Stored XSS vulnerability in Visualizer plugin affecting versions ≤3.9.1, exploitable by users with contributor-level permissions or higher. Malicious script payloads are persisted in the database and executed client-side when accessed by other users, potentially leading to session hijacking, credential theft, or privilege escalation.
Summary generated and translated by AI from the official description.
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Themeisle Visualizer: Tables and Charts Manager for WordPress plugin <= 3.9.1 versions.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Affected products
Themeisle · Visualizer: Tables and Charts Manager for WordPress