Description
Cross-Site Request Forgery (CSRF) vulnerability in Ays Pro Chartify chart-builder allows Cross Site Request Forgery.This issue affects Chartify: from n/a through <= 3.6.3.
Published: 2025-12-09
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Ays Pro Chartify chart‑builder plugin for WordPress and permits a Cross‑Site Request Forgery (CSRF) attack. An attacker can trick an authenticated user into performing unwanted actions through the plugin’s interface, potentially leading to unauthorized modification of chart data or settings. Because the flaw allows actions to be executed in the context of the logged‑in user, it can affect the page’s integrity and any data that the user is permitted to alter. The weakness is consistent with CWE‑352, a classic CSRF flaw.

Affected Systems

Installed instances of the WordPress Chartify plugin version 3.6.3 or earlier are affected. The advisory specifies that all releases from the earliest available version up to and including 3.6.3 contain the flaw. No specific vendor or product names beyond the Chartify chart‑builder are included, but the plugin developers are listed as Ays Pro.

Risk and Exploitability

The flaw carries a CVSS score of 4.3, indicating moderate risk, and the EPSS score is reported as less than 1 %, which shows a very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, further suggesting it has not been widely exploited. A likely attack path involves a compromised or spoofed website that loads the infected page in an authenticated user’s browser, where the CSRF token is missing or unchecked, enabling the attacker to trigger chart‑builder queries as that user. No special privileges are required beyond the normal, authentic user session of the target. Given the low EPSS, the risk is considered moderate but should still be mitigated promptly.

Generated by OpenCVE AI on April 29, 2026 at 19:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Chartify plugin to a version newer than 3.6.3
  • If an update cannot be applied immediately, ensure that all chart‑builder endpoints enforce a proper anti‑CSRF token or nonce that matches a session value
  • Disable or remove the chart‑builder functionalities for users who do not require them, or restrict access to the plugin’s administrative screens to the minimum set of roles

Generated by OpenCVE AI on April 29, 2026 at 19:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 29 Apr 2026 01:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Thu, 11 Dec 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 10 Dec 2025 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Ays-pro
Ays-pro chartify
Wordpress
Wordpress wordpress
Vendors & Products Ays-pro
Ays-pro chartify
Wordpress
Wordpress wordpress

Tue, 09 Dec 2025 14:30:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Ays Pro Chartify chart-builder allows Cross Site Request Forgery.This issue affects Chartify: from n/a through <= 3.6.3.
Title WordPress Chartify plugin <= 3.6.3 - Cross Site Request Forgery (CSRF) vulnerability
Weaknesses CWE-352
References

Subscriptions

Ays-pro Chartify
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:19.249Z

Reserved: 2025-12-04T04:07:13.046Z

Link: CVE-2025-66529

cve-icon Vulnrichment

Updated: 2025-12-11T19:04:04.681Z

cve-icon NVD

Status : Deferred

Published: 2025-12-09T16:18:20.157

Modified: 2026-04-27T18:16:38.357

Link: CVE-2025-66529

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T20:00:18Z

Weaknesses