Impact
The Graphina – Charts and Graphs For Elementor plugin for WordPress contains a stored cross‑site scripting flaw that allows an authenticated user with contributor-level access or higher to inject arbitrary JavaScript through the "iq_tree_tree_chart_template" widget setting. The injected script is persisted and executed whenever users view pages containing the affected chart. This vulnerability can expose sensitive data, deface content, or further compromise authenticated sessions, thereby affecting confidentiality, integrity, and availability of the site.
Affected Systems
WordPress sites running the Graphina plugin version 3.1.11 or any earlier release are affected. The vendor is iqonicdesign, product Graphina – Charts and Graphs For Elementor. No specific operating system or WordPress version requirements are listed beyond the plugin version, so all supported WordPress installations using this plugin may be impacted.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate severity. EPSS data is not available, so the current likelihood of exploitation is unknown, but the vulnerability is not listed in CISA’s KEV catalog. The attack vector is inferred to be an authenticated web application attack: an attacker must be able to log into the WordPress site with at least contributor privileges to modify widget settings. Once authorized, the malicious script is stored and will run for any visitor to the affected chart, giving the attacker the ability to execute arbitrary client‑side code.
OpenCVE Enrichment