PatchSiren cyber security CVE debrief
CVE-2026-8689 themeisle CVE debrief
A missing authorization vulnerability in the Visualizer: Tables and Charts Manager for WordPress plugin allows authenticated attackers with Subscriber-level access to create arbitrary chart posts and access or modify chart data belonging to other users. The vulnerability stems from missing capability checks on the renderChartPages() and uploadData() functions, which are invoked by AJAX actions without current_user_can() validation. Additionally, the uploadData() function's nonce validation lacks an action argument, making it trivially bypassable. The vulnerability affects all versions up to and including 3.11.14. A fix is available in version 4.0.1.
- Vendor
- themeisle
- Product
- Visualizer: Tables and Charts Manager for WordPress
- CVSS
- MEDIUM 4.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-28
- Original CVE updated
- 2026-05-28
- Advisory published
- 2026-05-28
- Advisory updated
- 2026-05-28
Who should care
WordPress site administrators using the Visualizer: Tables and Charts Manager plugin, particularly those with multi-user environments where Subscriber or low-privilege accounts exist. Security teams monitoring for unauthorized content creation or data manipulation in WordPress installations.
Technical summary
The Visualizer plugin registers AJAX handlers wp_ajax_visualizer-create-chart, wp_ajax_visualizer-edit-chart, and wp_ajax_visualizer-upload-data without proper capability verification. The renderChartPages() function (invoked by create-chart and edit-chart actions) and uploadData() function (invoked by upload-data action) both lack current_user_can() checks. The uploadData() function's nonce validation is further weakened by omitting the action parameter, allowing trivial bypass. This enables any authenticated user, including those with minimal Subscriber privileges, to create chart posts and manipulate chart data across user boundaries.
Defensive priority
medium
Recommended defensive actions
- Upgrade Visualizer: Tables and Charts Manager for WordPress plugin to version 4.0.1 or later
- Review existing chart posts for unauthorized modifications if running affected versions
- Implement principle of least privilege by auditing user roles and capabilities
- Consider implementing additional access controls at the web application firewall level for wp_ajax_visualizer-* endpoints until patching is complete
Evidence notes
The vulnerability was reported by Wordfence and documented in the NVD entry published 2026-05-28. Source code analysis confirms the missing capability checks in version 3.11.14 at lines 56, 531, and 1221 of classes/Visualizer/Module/Chart.php. The fix in version 4.0.1 addresses these issues at the same line numbers. A changeset (3474710) documents the security patch.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-8689 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-8689
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-8689 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-8689
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/visualizer/tags/3.11.14/classes/Visualizer/Module/Chart.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/visualizer/tags/3.11.14/classes/Visualizer/Module/Chart.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/visualizer/tags/3.11.14/classes/Visualizer/Module/Chart.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/visualizer/tags/4.0.1/classes/Visualizer/Module/Chart.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/visualizer/tags/4.0.1/classes/Visualizer/Module/Chart.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/visualizer/tags/4.0.1/classes/Visualizer/Module/Chart.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/changeset/3474710
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.