PatchSiren

Visualizer CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Visualizer CVE published 2026-08-16

CVE-2026-19726

The Visualizer WordPress plugin before 4.0.7 has a critical vulnerability allowing users with the Contributor role and above to read the full configuration of any chart on the site. This includes configurations that the plugin's own interface denies them access to. The disclosed configuration can include credentials of a remote data source that a chart reads from. This vulnerability has a CVSS score of 6. [truncated]