6.1

CVE-2019-16931

Exploit

Visualizer: Tables and Charts Manager for WordPress <= 3.3.0 - Stored Cross-Site Scripting

A stored XSS vulnerability in the Visualizer plugin 3.3.0 for WordPress allows an unauthenticated attacker to execute arbitrary JavaScript when an admin or other privileged user edits the chart via the admin dashboard. This occurs because classes/Visualizer/Gutenberg/Block.php registers wp-json/visualizer/v1/update-chart with no access control, and classes/Visualizer/Render/Page/Data.php lacks output sanitization.
Mögliche Gegenmaßnahme
Visualizer – Tables & Charts Manager with Built-in AI Generator: Update to version 3.3.1, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ThemeisleVisualizer SwPlatformwordpress Version <= 3.3.0
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Visualizer – Tables & Charts Manager with Built-in AI Generator
Version *-3.3.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.34% 0.871
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

https://nathandavison.com/blog/wordpress-visualizer-plugin-xss-and-ssrf
Third Party Advisory
Exploit
https://wordpress.org/plugins/visualizer/#developers
Product
Release Notes
https://wpvulndb.com/vulnerabilities/9893
Third Party Advisory
Exploit
https://www.wordfence.com/threat-intel/vulnerabilities/id/eaaf1ac0-1ea6-4bcb-a385-87267525801c
Third Party Advisory