CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 6.1. It affects WordPress, Java. Exploitation may require the attacker to be authenticated.
CVE
CVE-2019-16931
Severity
MEDIUM
CVSS
6.1
EPSS
3.34%
WordPress Java
Original NVD Description
A stored XSS vulnerability in the Visualizer plugin 3.3.0 for WordPress allows an unauthenticated attacker to execute arbitrary JavaScript when an admin or other privileged user edits the chart via the admin dashboard. This occurs because classes/Visualizer/Gutenberg/Block.php registers wp-json/visualizer/v1/update-chart with no access control, and classes/Visualizer/Render/Page/Data.php lacks output sanitization.
Related CVEs
Other vulnerabilities affecting the same vendor(s)