---
id: CVE-2026-86784
title: >-
  The Visualizer  WordPress plugin before 4.0.8 does not sanitise and escape a
  chart's JSON data source configuration before outputting it back in the chart
  editor, allowing users with the Contributor role and above to store JavaScript
  tha…
summary: >-
  The Visualizer  WordPress plugin before 4.0.8 does not sanitise and escape a
  chart's JSON data source configuration before outputting it back in the chart
  editor, allowing users with the Contributor role and above to store JavaScript
  tha…
severity: medium
cvss: 6.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-79
product: Visualizer
affected:
  - Visualizer < 4.0.8
published: '2026-09-16'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T13:16:53.590'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-86784'
references:
  - url: 'https://wpscan.com/vulnerability/9ac2d380-62fd-4967-8697-40175ffdf1c7/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-17T12:17:39.176573Z'
epss: 0.00431
epssPercentile: 0.34623
ingestedAt: '2026-09-16T06:51:06.254Z'
---

## Overview

The Visualizer  WordPress plugin before 4.0.8 does not sanitise and escape a chart's JSON data source configuration before outputting it back in the chart editor, allowing users with the Contributor role and above to store JavaScript that executes in the browser of any higher-privileged user, such as an administrator, who reviews the affected chart.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
