CVE-2019-16931
Visualizer: Tables and Charts Manager for WordPress <= 3.3.0 - Stored Cross-Site Scripting
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
A stored XSS vulnerability in the Visualizer plugin 3.3.0 for WordPress allows an unauthenticated attacker to execute arbitrary JavaScript when an admin or other privileged user edits the chart via the admin dashboard. This occurs because classes/Visualizer/Gutenberg/Block.php registers wp-json/visualizer/v1/update-chart with no access control, and classes/Visualizer/Render/Page/Data.php lacks output sanitization.
Una vulnerabilidad de tipo XSS almacenada en el plugin Visualizer versiĆ³n 3.3.0 para WordPress, permite a un atacante no autenticado ejecutar JavaScript arbitrario cuando un administrador u otro usuario privilegiado edita la tabla por medio del panel de administraciĆ³n. Esto ocurre porque classes/Visualizer/Gutenberg/Block.php registra wp-json/visualizer/v1/update-chart sin control de acceso, y classes/Visualizer/Render/Page/Data.php carece de saneamiento de la salida.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-09-27 CVE Reserved
- 2019-09-28 CVE Published
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- 2024-09-26 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://wordpress.org/plugins/visualizer/#developers | Product |
URL | Date | SRC |
---|---|---|
https://nathandavison.com/blog/wordpress-visualizer-plugin-xss-and-ssrf | 2024-08-05 | |
https://wpvulndb.com/vulnerabilities/9893 | 2024-08-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Themeisle Search vendor "Themeisle" | Visualizer Search vendor "Themeisle" for product "Visualizer" | <= 3.3.0 Search vendor "Themeisle" for product "Visualizer" and version " <= 3.3.0" | wordpress |
Affected
|