Junglewise Threat Intelligence

CVE-2026-13468: ThemeIsle Visualizer authorization bypass in REST API

CVE-2026-13468 · Severity: high · CVSS 7.5 · Published 2026-07-01

Technologies: Themeisle Visualizer – Tables & Charts Manager with Built-in AI Generator. Vendors: Themeisle.

Executive brief

A vulnerability in the Visualizer plugin for WordPress allows unauthorized individuals to access and download data from charts and tables. This includes sensitive information stored in private, draft, or deleted charts that were never intended for public viewing. An attacker can export this data in various formats like Excel or CSV without needing a password or account.

Technical details

The Visualizer plugin for WordPress (versions up to 4.0.3) contains an authorization bypass vulnerability due to missing capability checks on a custom-registered REST API route. While the standard WordPress REST endpoint for the 'visualizer' custom post type correctly enforces permissions, the plugin-specific route `/wp-json/visualizer/v1/action/{chart}/{type}/` does not. This allows unauthenticated remote attackers to bypass intended access controls and export chart data (including draft, private, pending, future, or trashed posts) as CSV, Excel, or HTML. The vulnerability is classified as CWE-862 (Missing Authorization).

Affected products

  • ThemeIsle Visualizer – Tables & Charts Manager with Built-in AI Generator up to, and including, 4.0.3

Timeline

  • 2026-07-01: disclosed
  • 2026-07-01: advisory

References

Related threats