Junglewise Threat Intelligence

CVE-2026-65529: Iqonic Design Graphina broken access control

CVE-2026-65529 · Severity: medium · CVSS 5.3 · Published 2026-07-23

Vendors: Iqonic Design.

Executive brief

Graphina is a WordPress plugin used to create interactive charts and graphs within the Elementor page builder. A security flaw in versions 3.1.12 and earlier allows unauthorized individuals to bypass access controls, potentially leading to the exposure of restricted information. While the impact is currently rated as medium, it could allow an attacker to view data they are not permitted to see without needing to log in.

Technical details

The Graphina plugin for WordPress (specifically the 'graphina-elementor-charts-and-graphs' package) is vulnerable to broken access control due to missing authorization checks (CWE-862). An unauthenticated remote attacker can exploit this flaw to perform actions or access data that should be restricted to higher-privileged users. The vulnerability exists in versions up to and including 3.1.12. As of the advisory date, no official patch has been confirmed, though users are advised to monitor for updates from Iqonic Design.

Affected products

  • Iqonic Design Graphina - Elementor Charts and Graphs <= 3.1.12

Timeline

  • 2026-06-10: other: Vulnerability reported by researcher Ananda Dhakal
  • 2026-07-23: disclosed: Vulnerability details published by Patchstack and NVD

References