CVE-2026-14939: Visualizer: Tables and Charts Manager < 4.0.6 - Contributor+ Server-Side Request Forgery via JSON Import
The Visualizer WordPress plugin before 4.0.6 does not restrict a user-supplied URL to safe address ranges before fetching it server-side, allowing users with Contributor-level access and above to perform Server-Side Request Forgery against link-local instance-metadata endpoints. As the fetched response is returned in the reply, the attack is non-blind, enabling retrieval of cloud instance metadata (including IAM credentials) on cloud-hosted sites.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Visualizer WordPress plugin (Visualizer: Tables and Charts Manager)to a version that resolves this vulnerability.Fixed in 4.0.6 - Compensating control
Restrict access to the Visualizer plugin’s JSON import/contributor-level functionality to trusted users only to reduce the ability to trigger SSRF against link-local instance-metadata endpoints.