CVE-2026-86782
The Visualizer WordPress plugin before 4.0.6 does not properly authorise access to its chart-building actions, allowing users with the Contributor role and above to publish, rename, and overwrite the content of posts and pages they do not own, including other users' private drafts.
- Published Sep 11, 2026
- CVSS 5.5 medium
- 0.3% chance of exploitation in the next 30 days (EPSS)
- A fix is available