Visualizer < 4.0.7 - Contributor+ Cross-User Chart Configuration Disclosure
Summary
| CVE | CVE-2026-19726 |
|---|---|
| State | PUBLISHED |
| Assigner | WPScan |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-16 06:16:52 UTC |
| Updated | 2026-08-16 06:16:52 UTC |
| Description | The Visualizer WordPress plugin before 4.0.7 does not properly authorise access to the configuration of its charts, allowing users with the Contributor role and above to read the full configuration of any chart on the site, including charts the Visualizer WordPress plugin before 4.0.7's own interface denies them, and to retrieve every chart's configuration in a single request. The disclosed configuration can include the credentials of a remote data source a chart reads from. |
Risk And Classification
Problem Types: CWE-863 Incorrect Authorization
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Unknown | Visualizer | affected 4.0.7 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| wpscan.com/vulnerability/61a1577e-077f-4a00-96b4-860eda48e03b | [email protected] | wpscan.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Farid Narimanov (en)
CNA: WPScan (en)
There are currently no legacy QID mappings associated with this CVE.