CVE-2026-86784: Visualizer < 4.0.8 - Contributor+ Stored XSS via JSON Data Source
The Visualizer WordPress plugin before 4.0.8 does not sanitise and escape a chart's JSON data source configuration before outputting it back in the chart editor, allowing users with the Contributor role and above to store JavaScript that executes in the browser of any higher-privileged user, such as an administrator, who reviews the affected chart.
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Visualizer pluginto a version that resolves this vulnerability.Fixed in 4.0.8
Event History
Frequently Asked Questions
Which users can exploit this issue, and who is at risk from the payload?
Any user with the Contributor role or a higher role can store malicious JavaScript in a chart's JSON data source configuration. The JavaScript executes when a higher-privileged user, such as an administrator, reviews the affected chart in the browser.
What product versions are affected?
Visualizer versions before 4.0.8 are affected. Updating to version 4.0.8 or later removes the described vulnerable version range.
How can an administrator determine whether they may have been targeted?
Review charts created or edited by Contributor-level and other non-administrative users, focusing on their JSON data source configuration. The issue is triggered when the affected chart is opened in the chart editor by a higher-privileged user.