← back
CVE-2026-86782mediumCWE-639

Visualizer < 4.0.6 - Contributor+ Arbitrary Post/Page Modification via IDOR

33Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 5.5epss 0.3%
exploitation probability
0.3%top 79% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The Visualizer WordPress plugin before 4.0.6 does not properly authorise access to its chart-building actions, allowing users with the Contributor role and above to publish, rename, and overwrite the content of posts and pages they do not own, including other users' private drafts.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:N
Affected products
Unknown · Visualizer
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.