Showing 2 vulnerabilities on this page for Chartify – WordPress Chart Plugin

Signals CISA KEV Ransomware Nuclei
ays-pro vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Chartify – WordPress Chart Plugin <= 3.5.9 - Missing Authentication for Administrative Function

The Chartify – WordPress Chart Plugin for WordPress is vulnerable to Missing Authentication for Critical Function in all versions up to, and including, 3.5.9. This is due to the plugin registering an unauthenticated AJAX action that dispatches to admin-class methods based on a request parameter, without any nonce or capability checks. This makes it possible for unauthenticated attackers to execute administrative functions via the wp-admin/admin-ajax.php endpoint granted they can identify callabl

CWE-306Oct 8, 2025
CVSS5.3v3.1EPSS0.327%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Chartify – WordPress Chart Plugin <= 2.9.5 - Unauthenticated Local File Inclusion via source

The Chartify – WordPress Chart Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.9.5 via the 'source' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and includ

CWE-98Nov 14, 20241 related artifact
CVSS9.8v3.1EPSS4.84%PoCs1SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX