CVE-2026-19726
Visualizer < 4.0.7 - Contributor+ Cross-User Chart Configuration Disclosure
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Visualizer WordPress plugin before 4.0.7 does not properly authorise access to the configuration of its charts, allowing users with the Contributor role and above to read the full configuration of any chart on the site, including charts the Visualizer WordPress plugin before 4.0.7's own interface denies them, and to retrieve every chart's configuration in a single request. The disclosed configuration can include the credentials of a remote data source a chart reads from.
| Vendor | unknown |
| Product | visualizer |
| Published | Aug 16, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown visualizer
Be the first to know when new unknown vulnerabilities affecting unknown visualizer are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Visualizer
0 < 4.0.7
References
Credits
Farid Narimanov WPScan