{"id":"CVE-2026-86779","title":"The Visualizer  WordPress plugin before 4.0.6 does not properly authorise chart-deletion requests, performing only a site-wide capability check with no per-object ownership verification, allowing users with the Contributor role and above…","summary":"The Visualizer  WordPress plugin before 4.0.6 does not properly authorise chart-deletion requests, performing only a site-wide capability check with no per-object ownership verification, allowing users with the Contributor role and above…","severity":"low","cvss":2.7,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N","cwe":["CWE-862"],"product":"Visualizer","affected":["Visualizer < 4.0.6"],"published":"2026-09-11","updated":"2026-09-11","sourceUpdated":"2026-09-11T17:35:21.440","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-86779","references":[{"url":"https://wpscan.com/vulnerability/12a30aca-9b78-4ee8-9cf0-29e579ea5a0b/","label":"contact@wpscan.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-11T10:01:47.676037Z"},"epss":0.00168,"epssPercentile":0.0655,"ingestedAt":"2026-09-11T16:45:47.924Z","slug":"CVE-2026-86779","body":"## Overview\n\nThe Visualizer  WordPress plugin before 4.0.6 does not properly authorise chart-deletion requests, performing only a site-wide capability check with no per-object ownership verification, allowing users with the Contributor role and above to permanently delete any chart on the site, including charts created by other users such as administrators.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":15,"depthScoreParts":{"impact":14.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}