Junglewise Threat Intelligence

CVE-2026-24573: Themeisle Visualizer Stored XSS in WordPress plugin

CVE-2026-24573 · Severity: medium · CVSS 6.5 · Published 2026-05-20

Technologies: Themeisle Visualizer. Vendors: Themeisle.

Executive brief

Themeisle Visualizer, a popular WordPress plugin for creating charts and graphs, contains a security flaw that allows users with low-level permissions to inject malicious scripts into the website. If an administrator or visitor views the affected content, these scripts could execute in their browser, potentially leading to unauthorized actions, data theft, or website defacement. This issue is resolved in version 4.0.0.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability exists in the Themeisle Visualizer plugin for WordPress in versions prior to 4.0.0. The flaw stems from improper neutralization of user-supplied input during web page generation (CWE-79). An attacker with 'Contributor' or higher privileges can inject malicious JavaScript payloads into chart configurations or other metadata. These scripts are then executed in the context of a victim's browser (such as a site administrator) when they interact with or view the affected content. The vulnerability requires user interaction and has been patched in version 4.0.0.

Affected products

  • Themeisle Visualizer before 4.0.0

Timeline

  • 2025-12-22: other: Reported by Doan Dinh Van
  • 2026-05-20: patched: Version 4.0.0 released
  • 2026-05-20: advisory: Published by Patchstack and NVD

References

Related threats