PT-2026-73127 · WordPress · Visualizer
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Visualizer versions prior to 4.0.7
Description
Insufficient authorization in the plugin allows users with the Contributor role and above to read the full configuration of any chart on the site. This includes charts that the interface normally restricts and allows the retrieval of all chart configurations in a single request. The exposed configuration may contain credentials for remote data sources used by the charts.
Recommendations
Update to version 4.0.7 or later.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Visualizer