PT-2026-44219 · Themeisle · The Visualizer: Tables/Charts Manager For Wordpress

Published

2026-05-28

·

Updated

2026-05-28

·

CVE-2026-8689

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.11.14. This is due to a missing capability check on the renderChartPages() and uploadData() functions, where the wp ajax visualizer-create-chart and wp ajax visualizer-edit-chart AJAX actions invoke renderChartPages() without any current user can() check, and wp ajax visualizer-upload-data invokes uploadData() which also lacks a capability check and validates its nonce without an action argument, making it trivially bypassable. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create arbitrary chart posts and access or modify chart data belonging to other users, including administrators.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-8689

Affected Products

The Visualizer: Tables/Charts Manager For Wordpress