AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2019-16931

MEDIUM · CVSS 6.1 EPSS 3.34%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2019-10-03 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 6.1. It affects WordPress, Java. Exploitation may require the attacker to be authenticated.

CVE
CVE-2019-16931
Severity
MEDIUM
CVSS
6.1
EPSS
3.34%
WordPress Java

Original NVD Description

A stored XSS vulnerability in the Visualizer plugin 3.3.0 for WordPress allows an unauthenticated attacker to execute arbitrary JavaScript when an admin or other privileged user edits the chart via the admin dashboard. This occurs because classes/Visualizer/Gutenberg/Block.php registers wp-json/visualizer/v1/update-chart with no access control, and classes/Visualizer/Render/Page/Data.php lacks output sanitization.

Related CVEs

Other vulnerabilities affecting the same vendor(s)