MEDIUM
Visualizer
CVE published 2026-08-16
CVE-2026-19726
The Visualizer WordPress plugin before 4.0.7 has a critical vulnerability allowing users with the Contributor role and above to read the full configuration of any chart on the site. This includes configurations that the plugin's own interface denies them access to. The disclosed configuration can include credentials of a remote data source that a chart reads from. This vulnerability has a CVSS score of 6. [truncated]