Executive brief
Graphina is a WordPress plugin that adds charting and graphing capabilities to the Elementor page builder. A stored cross-site scripting vulnerability in the tree chart widget allows authenticated users with contributor-level permissions to inject malicious scripts into pages. When other users (including administrators) view the affected page, the injected scripts execute in their browsers, potentially compromising their accounts or stealing sensitive data.
Technical details
The vulnerability is a stored XSS flaw in the 'iq_tree_tree_chart_template' widget setting, caused by insufficient input sanitization and output escaping. Authenticated attackers with contributor-level access or higher can inject arbitrary JavaScript code into the widget configuration. The injected payload persists in the database and executes whenever any user accesses a page containing the compromised widget. No network-level exploit complexity is required beyond standard WordPress authentication. A patch is available in versions after 3.1.11.
Affected products
- Graphina Charts and Graphs For Elementor up to and including 3.1.11
Timeline
- 2026-09-09: disclosed