Impact
The Visualizer plugin before version 4.0.6 fails to enforce per‑object ownership when processing chart‑deletion requests, performing only a site‑wide capability check. This allows any user with the Contributor role or higher to permanently delete any chart on the site, including those created by administrators. The weakness is a CWE‑862 (Missing Authorization), leading to loss of chart data, disrupting site functionality, violating content integrity, and potentially acting as a denial‑of‑service vector by removing all visual content.
Affected Systems
WordPress sites running the Visualizer plugin version 4.0.6 or earlier are impacted. The vulnerability exists regardless of other plugins or themes installed.
Risk and Exploitability
The severity is low with a CVSS score of 2.7 but the exploitability is high because it only requires an authenticated Contributor or higher role and an HTTP request to the deleteChart endpoint. An attacker can easily send a request from the browser or via an automated script to delete any chart, undermining site content and availability. The EPSS score is below 1% and the vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment