Impact
The Visualizer plugin contains a stored cross‑site scripting flaw that allows an authenticated attacker with contributor or higher level access to embed malicious scripts into imported data files. The plugin fails to properly sanitize and escape user supplied attributes, so the attacker can insert XSS payloads that are rendered when anyone views the affected page. This can lead to theft of user credentials, session hijacking, or site defacement. The weakness corresponds to CWE‑79.
Affected Systems
The vulnerable product is Themeisle’s Visualizer: Tables and Charts Manager for WordPress. All releases up to and including version 3.11.8 are affected. Users running these versions should verify the plugin version and apply an update if available.
Risk and Exploitability
With a CVSS score of 6.4 the risk is moderate and the EPSS score of less than 1% indicates low exploitation likelihood in the current landscape. The vulnerability is not listed in the CISA KEV catalog. Attacking requires an authenticated contributor‑level account; once inside, the attacker can inject scripts that execute for any visitor to the polluted page, potentially impacting confidentiality and integrity of user data.
OpenCVE Enrichment
EUVD