Executive brief
The WpDevArt Organization chart plugin for WordPress, which is used to create and display company hierarchies, contains a security flaw that could allow an attacker to trick an administrator into performing unintended actions. By convincing a logged-in user to click a malicious link or visit a specific webpage, an attacker could modify plugin settings or data without the user's consent. This could lead to unauthorized changes to the organization charts displayed on the website.
Technical details
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WpDevArt Organization chart plugin for WordPress (versions <= 1.7.5) due to insufficient validation of request origins on sensitive administrative functions. An unauthenticated remote attacker can exploit this by crafting a malicious request and tricking a site administrator or other privileged user into executing it via social engineering (e.g., a malicious link). Successful exploitation allows the attacker to perform actions on behalf of the authenticated user, such as modifying or deleting organization chart data. The issue is addressed in version 1.7.6.
Affected products
- WpDevArt Organization chart n/a through 1.7.5
Timeline
- 2025-12-16: other: Reported by researcher daroo
- 2026-05-25: advisory: Published by Patchstack and NVD
- 2026-05-25: patched: Fixed in version 1.7.6