Impact
There is a stored cross‑site scripting vulnerability in the Visualizer WordPress plugin that allows a user with the Contributor role or higher to embed arbitrary JavaScript in a chart’s JSON data source. The plugin fails to sanitize or escape the JSON configuration before it is displayed in the chart editor, so the malicious code executes in the browser of any user who later opens the editor, including administrators. Because the data is persistently stored, the vulnerability can lead to persistent compromise of privileged sessions, defacement, or credential theft for the affected site.
Affected Systems
The bug affects all installations of the Visualizer plugin that are version 4.0.7 or earlier. No vendor is officially listed; the product is a WordPress plugin named Visualizer. Administrators or users with Contributor status can create the charts that contain malicious payloads. The specific version and patch status are not stated beyond the 4.0.8 release, but any version prior to that is considered vulnerable.
Risk and Exploitability
The CVSS score is not provided, but the EPSS score is below 1%, indicating a low public exploit probability at present. The vulnerability is not listed in CISA's KEV catalog, so no known widespread exploitation has been reported. Nonetheless, because the flaw allows persistent malicious scripts to run in the context of higher‑privileged users, the potential impact is high. The attack can be carried out by any Contributor or higher who has write access to chart data; an attacker could inject JavaScript that runs in the browser of any administrator who edits or views the chart. Remediation is best achieved by applying the available plugin update.
OpenCVE Enrichment