🔐 CVE Alert

CVE-2025-11171

MEDIUM 5.3

Chartify – WordPress Chart Plugin <= 3.5.9 - Missing Authentication for Administrative Function

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

The Chartify – WordPress Chart Plugin for WordPress is vulnerable to Missing Authentication for Critical Function in all versions up to, and including, 3.5.9. This is due to the plugin registering an unauthenticated AJAX action that dispatches to admin-class methods based on a request parameter, without any nonce or capability checks. This makes it possible for unauthenticated attackers to execute administrative functions via the wp-admin/admin-ajax.php endpoint granted they can identify callable method names.

CWE CWE-306
Vendor ays-pro
Product chartify – wordpress chart plugin
Published Oct 8, 2025
Last Updated Apr 8, 2026
Stay Ahead of the Next One

Get instant alerts for ays-pro chartify – wordpress chart plugin

Be the first to know when new medium vulnerabilities affecting ays-pro chartify – wordpress chart plugin are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

ays-pro / Chartify – WordPress Chart Plugin
0 ≤ 3.5.9

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/aa3e030b-8ef1-4dbc-940d-6c2ab2683620?source=cve plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/chart-builder/tags/3.5.8/includes/class-chart-builder.php#L247 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/chart-builder/tags/3.5.8/admin/class-chart-builder-admin.php#L675 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/chart-builder/tags/3.5.8/admin/class-chart-builder-admin.php#L1625 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3372188%40chart-builder%2Ftags%2F3.6.0&new=3372188%40chart-builder%2Ftags%2F3.6.0

Credits

Avraham Shemesh Kai Aizen