CyberRota Analysis
AI-GeneratedThe Visualizer WordPress plugin prior to version 4.0.6 is vulnerable to improper authorization in chart-deletion requests, allowing users with Contributor roles and higher to delete any chart on the site, regardless of ownership. This could lead to the permanent loss of important data, including charts created by administrators. WordPress site administrators and security teams should prioritize updating this plugin to mitigate the risk of unauthorized data deletion.
Original NVD Description
The Visualizer WordPress plugin before 4.0.6 does not properly authorise chart-deletion requests, performing only a site-wide capability check with no per-object ownership verification, allowing users with the Contributor role and above to permanently delete any chart on the site, including charts created by other users such as administrators.