Visualizer – Tables & Charts Manager with Built-in AI Generator

Information

Software Type Plugin
Software Slug visualizer (view on wordpress.org)
Software Status Active
Software Author themeisle
Software Website themeisle.com
Software Downloads 2,062,987
Software Active Installs 20,000
Software Record Last Updated August 12, 2026

19 Vulnerabilities

6.1
CVE ID Unknown
May 31, 2022
Researcher: WPScanTeam
Title Status CVE ID CVSS Researchers Date
Visualizer <= 4.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'backend-title' Parameter Patched CVE-2026-15653 6.4 Wordfence PRISM July 23, 2026
Visualizer – Tables & Charts Manager with Built-in AI Generator <= 4.0.1 - Authenticated (Contributor+) SQL Injection Patched CVE-2026-65526 6.5 ParkHyunWoo July 23, 2026
Visualizer <= 4.0.3 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via /visualizer/v1/action/{chart}/{type}/ REST Endpoint Patched CVE-2026-13468 7.5 Niv Kochan June 30, 2026
Visualizer: Tables and Charts Manager for WordPress <= 3.11.14 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Chart Creation and Modification via renderChartPages() and uploadData() Functions Patched CVE-2026-8689 4.3 davidfdzmorilla May 27, 2026
Visualizer: Tables and Charts Manager for WordPress < 4.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting Patched CVE-2026-24573 6.4 Doan Dinh Van (d52v) May 20, 2026
Visualizer: Tables and Charts Manager for WordPress <= 3.11.12 - Authenticated (Contributor+) SQL Injection Patched CVE-2025-12483 6.5 Rafshanzani Suhada December 1, 2025
Visualizer: Tables and Charts Manager for WordPress <= 3.11.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Import Data From File Patched CVE-2025-1065 6.4 Webbernaut February 18, 2025
PHPSpreadsheet Library < 2.3.0 - XXE Injection Patched CVE-2024-45293 7.5 October 7, 2024
Visualizer <= 3.11.1 - Authenticated (Subscriber+) SQL Injection Patched CVE-2024-35736 9.9 Trương Hữu Phúc (truonghuuphuc) June 6, 2024
Visualizer: Tables and Charts Manager for WordPress <= 3.10.15 - Missing Authorization to Arbitrary SQL Execution Patched CVE-2024-3750 8.8 Krzysztof Zając May 15, 2024
Visualizer <= 3.10.5 - Reflected Cross-Site Scripting Patched CVE-2024-27958 6.1 stealthcopter March 13, 2024
ThemeIsle SDK <= Various Versions - Missing Authorization Patched CVE-2024-1047 5.3 Francesco Carlucci February 1, 2024
Visualizer <= 3.9.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcodes Patched CVE-2023-23708 6.4 Rafshanzani Suhada February 20, 2023
Visualizer <= 3.9.1 - Authenticated(Contributor+) Stored Cross-Site Scripting Patched CVE-2022-46848 6.4 Muhammad Daffa February 6, 2023
Visualizer: Tables and Charts Manager for WordPress <= 3.7.9 - Authenticated (Contributor+) PHAR Deserialization Patched CVE-2022-2444 8.8 Rasoul Jahanshahi July 5, 2022
Visualizer: Tables and Charts Manager for WordPress <= 3.7.9 - Authenticated (Contributor+) PHAR Deserialization Patched CVE-2022-2256 8.8 July 5, 2022
Visualizer <= 3.7.6 - Reflected Cross-Site Scripting Patched 6.1 WPScanTeam May 31, 2022
Visualizer: Tables and Charts Manager for WordPress <= 3.3.0 - Server-Side Request Forgery Patched CVE-2019-16932 9.3 Nathan Davison September 28, 2019
Visualizer: Tables and Charts Manager for WordPress <= 3.3.0 - Stored Cross-Site Scripting Patched CVE-2019-16931 6.1 Nathan Davison September 28, 2019

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation