Junglewise Threat Intelligence

CVE-2026-65526: Themeisle Visualizer SQL injection in WordPress plugin

CVE-2026-65526 · Severity: high · CVSS 8.5 · Published 2026-07-23

Technologies: Themeisle Visualizer. Vendors: Themeisle.

Executive brief

Visualizer, a popular WordPress plugin used for creating interactive charts and tables, contains a security vulnerability that could allow users with 'Contributor' level access to execute unauthorized database commands. An attacker could exploit this to steal sensitive information from the website's database or disrupt site operations. This is particularly concerning for sites that allow multiple users to contribute content, as it bypasses standard security boundaries.

Technical details

A SQL injection vulnerability exists in the Themeisle Visualizer plugin for WordPress (versions <= 4.0.6) due to improper neutralization of special elements used in SQL commands (CWE-89). The flaw is accessible to authenticated users with 'Contributor' or higher privileges. By sending specially crafted requests, a remote attacker can bypass intended query logic to interact directly with the underlying database. This can lead to unauthorized data exfiltration or limited denial of service. At the time of the advisory, no official patch has been confirmed, though users are advised to monitor for updates from the vendor.

Affected products

  • Themeisle Visualizer <= 4.0.6

Timeline

  • 2026-05-04: other: Vulnerability reported by researcher ParkHyunWoo
  • 2026-07-23: disclosed: Vulnerability details published by Patchstack and NVD

References

Related threats