Impact
The Vulnerable Visualizer – Tables & Charts Manager with Built‑in AI Generator WordPress plugin allows any authenticated user with contributor or higher privileges to store arbitrary JavaScript in the "backend‑title" parameter of a chart. Due to insufficient input sanitization and missing output escaping, the injected code is later rendered as part of the chart page and executed in the browsers of any visitor who loads that page, allowing the attacker to run client‑side scripts without further action.
Affected Systems
WordPress installations that have themeisle’s Visualizer plugin installed in any version up to and including 4.0.5. Any site that permits contributors or higher roles to create or edit charts is potentially vulnerable.
Risk and Exploitability
The flaw carries a CVSS score of 6.4, indicating moderate severity, and an EPSS score of less than 1%, suggesting low but non‑zero exploitation probability. The issue is not listed in the CISA KEV catalog. An adversary must first authenticate with contributor‑level or higher privileges; once the malicious "backend‑title" value is stored, the script executes automatically for every user who views the affected chart, enabling the attacker to execute arbitrary client‑side code, potentially leading to credential theft, defacement, or phishing.
OpenCVE Enrichment