Description
The Graphina – Charts and Graphs For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'iq_tree_tree_chart_template' Widget Setting in all versions up to, and including, 3.1.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Published: 2026-09-09
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Apply Patch
AI Analysis

Impact

The Graphina – Charts and Graphs For Elementor plugin for WordPress contains a stored cross‑site scripting flaw that allows an authenticated user with contributor-level access or higher to inject arbitrary JavaScript through the "iq_tree_tree_chart_template" widget setting. The injected script is persisted and executed whenever users view pages containing the affected chart. This vulnerability can expose sensitive data, deface content, or further compromise authenticated sessions, thereby affecting confidentiality, integrity, and availability of the site.

Affected Systems

WordPress sites running the Graphina plugin version 3.1.11 or any earlier release are affected. The vendor is iqonicdesign, product Graphina – Charts and Graphs For Elementor. No specific operating system or WordPress version requirements are listed beyond the plugin version, so all supported WordPress installations using this plugin may be impacted.

Risk and Exploitability

The CVSS score of 6.4 indicates a moderate severity. EPSS data is not available, so the current likelihood of exploitation is unknown, but the vulnerability is not listed in CISA’s KEV catalog. The attack vector is inferred to be an authenticated web application attack: an attacker must be able to log into the WordPress site with at least contributor privileges to modify widget settings. Once authorized, the malicious script is stored and will run for any visitor to the affected chart, giving the attacker the ability to execute arbitrary client‑side code.

Generated by OpenCVE AI on September 9, 2026 at 04:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Graphina plugin to version 3.1.12 or later to remove the XSS flaw.
  • If an upgrade is not immediately possible, remove or disable the "iq_tree_tree_chart_template" widget setting and delete any charts containing custom templates to eliminate stored script content.
  • Restrict contributor or lower level user roles from editing widget settings or use an additional role‑based access control plugin to prevent unauthorized configuration changes.

Generated by OpenCVE AI on September 9, 2026 at 04:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Iqonicdesign
Iqonicdesign graphina – Charts And Graphs For Elementor
Wordpress
Wordpress wordpress
Vendors & Products Iqonicdesign
Iqonicdesign graphina – Charts And Graphs For Elementor
Wordpress
Wordpress wordpress

Wed, 09 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Description The Graphina – Charts and Graphs For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'iq_tree_tree_chart_template' Widget Setting in all versions up to, and including, 3.1.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Title Graphina <= 3.1.11 - Authenticated (Author+) Stored Cross-Site Scripting via 'iq_tree_tree_chart_template' Widget Setting
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Iqonicdesign Graphina – Charts And Graphs For Elementor
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-09T13:13:59.123Z

Reserved: 2026-06-29T13:30:50.649Z

Link: CVE-2026-13709

cve-icon Vulnrichment

Updated: 2026-09-09T13:13:53.481Z

cve-icon NVD

Status : Deferred

Published: 2026-09-09T03:17:22.770

Modified: 2026-09-09T15:33:47.627

Link: CVE-2026-13709

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T20:02:42Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')