SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-86779

LOW · CVSS 2.7 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-09-11 · Last synced 2026-09-13

CyberRota Analysis

AI-Generated

The Visualizer WordPress plugin prior to version 4.0.6 is vulnerable to improper authorization in chart-deletion requests, allowing users with Contributor roles and higher to delete any chart on the site, regardless of ownership. This could lead to the permanent loss of important data, including charts created by administrators. WordPress site administrators and security teams should prioritize updating this plugin to mitigate the risk of unauthorized data deletion.

CVE
CVE-2026-86779
Severity
LOW
CVSS
2.7
EPSS
0.17%
WordPress

Original NVD Description

The Visualizer WordPress plugin before 4.0.6 does not properly authorise chart-deletion requests, performing only a site-wide capability check with no per-object ownership verification, allowing users with the Contributor role and above to permanently delete any chart on the site, including charts created by other users such as administrators.