cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forchart-builder chart-builder

Direction: ascending
Jun 07, 2024

Chartify – WordPress Chart Plugin # c87fdad965ab0e4d1dd47c82eba48973a2f277ef

Date
Nov 28, 2023
Research Description
Chartify &#8211; WordPress Chart Plugin [chart-builder] < 1.9.7 Chart Builder <= 1.9.6 - Authenticated (Admin+) Stored Cross-Site Scripting The Best Chart Plugin – Chartify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.9.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
Affected versions
max 1.9.7.
Status
vulnerable

Chartify &#8211; WordPress Chart Plugin # CVE-2023-47526

CVE, Research URL

CVE-2023-47526

Date
Feb 12, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chart Builder Team Chartify – WordPress Chart Plugin allows Stored XSS.This issue affects Chartify – WordPress Chart Plugin: from n/a through 2.0.6.
Affected versions
max 1.9.7.
Status
vulnerable
Oct 01, 2024

Chartify &#8211; WordPress Chart Plugin # CVE-2024-47347

CVE, Research URL

CVE-2024-47347

Date
Oct 06, 2024
Research Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Chart Builder Team Chartify allows Reflected XSS.This issue affects Chartify: from n/a through 2.7.6.
Affected versions
max 2.7.7.
Status
vulnerable
Nov 14, 2024

Chartify &#8211; WordPress Chart Plugin # CVE-2024-10571

CVE, Research URL

CVE-2024-10571

Date
Nov 14, 2024
Research Description
The Chartify – WordPress Chart Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.9.5 via the 'source' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.
Affected versions
max 2.9.6.
Status
vulnerable
Apr 02, 2025

Chartify &#8211; WordPress Chart Plugin # CVE-2025-30904

CVE, Research URL

CVE-2025-30904

Date
Mar 27, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Chartify allows Stored XSS. This issue affects Chartify: from n/a through 3.1.7.
Affected versions
max 3.1.9.
Status
vulnerable
Aug 05, 2025

Chartify &#8211; WordPress Chart Plugin # CVE-2025-54673

CVE, Research URL

CVE-2025-54673

Date
Aug 14, 2025
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in Ays Pro Chartify allows Cross Site Request Forgery. This issue affects Chartify: from n/a through 3.5.3.
Affected versions
max 3.5.4.
Status
vulnerable
Nov 11, 2025

Chartify &#8211; WordPress Chart Plugin # CVE-2025-11171

CVE, Research URL

CVE-2025-11171

Date
Oct 08, 2025
Research Description
The Chartify – WordPress Chart Plugin for WordPress is vulnerable to Missing Authentication for Critical Function in all versions up to, and including, 3.5.9. This is due to the plugin registering an unauthenticated AJAX action that dispatches to admin-class methods based on a request parameter, without any nonce or capability checks. This makes it possible for unauthenticated attackers to execute administrative functions via the wp-admin/admin-ajax.php endpoint granted they can identify callable method names.
Affected versions
max 3.6.0.
Status
vulnerable