CVE-2026-14939: Visualizer: Tables and Charts Manager < 4.0.6 - Contributor+ Server-Side Request Forgery via JSON Import
The Visualizer WordPress plugin before 4.0.6 does not restrict a user-supplied URL to safe address ranges before fetching it server-side, allowing users with Contributor-level access and above to perform Server-Side Request Forgery against link-local instance-metadata endpoints. As the fetched response is returned in the reply, the attack is non-blind, enabling retrieval of cloud instance metadata (including IAM credentials) on cloud-hosted sites.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Visualizer WordPress plugin (Visualizer: Tables and Charts Manager)to a version that resolves this vulnerability.Fixed in 4.0.6 - Compensating control
Restrict access to the Visualizer plugin’s JSON import/contributor-level functionality to trusted users only to reduce the ability to trigger SSRF against link-local instance-metadata endpoints.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14939?
CVE-2026-14939 has a risk rating of 73, indicating a high severity level.
How do I fix CVE-2026-14939?
To fix CVE-2026-14939, update the Visualizer WordPress plugin to version 4.0.6 or later.
Who is affected by CVE-2026-14939?
CVE-2026-14939 affects users with Contributor-level access or higher using Visualizer plugin versions before 4.0.6.
What type of vulnerability is CVE-2026-14939?
CVE-2026-14939 is a Server-Side Request Forgery (SSRF) vulnerability.
What does CVE-2026-14939 allow an attacker to do?
CVE-2026-14939 allows attackers to perform Server-Side Request Forgery against link-local instance-metadata endpoints.