Junglewise Threat Intelligence

CVE-2026-14939: The Visualizer WordPress plugin SSRF in JSON import

CVE-2026-14939 · Severity: medium · CVSS 6.8 · Published 2026-08-04

Executive brief

The Visualizer WordPress plugin, used to create interactive charts and tables in WordPress sites, contains a server-side request forgery (SSRF) vulnerability in its JSON import feature. Attackers with Contributor-level permissions can exploit this to query sensitive cloud metadata endpoints on cloud-hosted sites, potentially exposing IAM credentials and other sensitive instance information. This primarily threatens WordPress sites running on AWS, GCP, or Azure infrastructure.

Technical details

The vulnerability exists in the JSON import functionality (wp-admin/admin-ajax.php actions "visualizer-json-get-data" and "visualizer-json-get-roots") which fetches remote URLs without properly validating them against safe address ranges. Although the plugin uses WordPress's safe HTTP function that blocks loopback (127.0.0.1) and RFC1918 private ranges, it fails to block the link-local 169.254.0.0/16 range, allowing access to cloud metadata endpoints. An authenticated user with Contributor role or above can supply a malicious URL parameter to fetch cloud instance metadata; the response is reflected back in the reply, enabling non-blind SSRF attacks to retrieve IAM credentials and other sensitive data. The vulnerability was fixed in version 4.0.6.

Affected products

  • ThemeRiver The Visualizer before 4.0.6

Timeline

  • 2026-07-27: disclosed
  • 2026-08-04: patched: Fixed in version 4.0.6

References