What is CVE-2026-15653?
The Visualizer – Tables & Charts Manager with Built-in AI Generator plugin for WordPress contains a Stored Cross-Site Scripting vulnerability via the 'backend-title' parameter. This affects all versions up to and including 4.0.5, allowing authenticated users to inject malicious scripts due to insufficient input sanitization and output escaping. Immediate update to the latest version is strongly recommended.
Azərbaycanca: "The Visualizer – Tables & Charts Manager with Built-in AI Generator" WordPress plagini "backend-title" parametrində Saxlanılan Cross-Site Scripting (XSS) zəifliyinə malikdir. Bu zəiflik 4.0.5 daxil olmaqla bütün versiyalara təsir edir və autentifikasiya olunmuş istifadəçilərə zərərli skript yerləşdirməyə imkan verir. Plagini dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which WordPress plugin is affected by CVE-2026-15653?
This vulnerability affects the "The Visualizer – Tables & Charts Manager with Built-in AI Generator" plugin.
Is authentication required to exploit CVE-2026-15653?
Yes, exploiting this Stored XSS vulnerability requires an authenticated user.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.