CVE-2026-19726

Visualizer < 4.0.7 - Contributor+ Cross-User Chart Configuration Disclosure

The Visualizer WordPress plugin before 4.0.7 does not properly authorise access to the configuration of its charts, allowing users with the Contributor role and above to read the full configuration of any chart on the site, including charts the Visualizer WordPress plugin before 4.0.7's own interface denies them, and to retrieve every chart's configuration in a single request. The disclosed configuration can include the credentials of a remote data source a chart reads from.


We have discovered 425 live websites that are affected by CVE-2026-19726.

Run a Free Instant Scan




Affected Software

Product  Visualizer
Category Wordpress Plugins
Vulnerable Domains425 live websites (98% of Visualizer install base)
Vulnerable Versions
  • from 0 through 4.0.7
Vulnerable Versions Count48 versions ( 98% of all versions)


Common Weakness Enumeration

CWE-863 Incorrect Authorization



Details

  • Published - Aug 16, 2026
  • Updated - Aug 17, 2026

Credits

  • Farid Narimanov (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2026-19726
United States139 websites



Germany33 websites
France24 websites
Japan17 websites
Italy16 websites
Switzerland14 websites
GB13 websites
Spain12 websites
Netherlands11 websites
Russia11 websites

Website Distribution by TLD

Number of websites using CVE-2026-19726
.com158 websites
.org50 websites
.de24 websites
.ch11 websites
.fr11 websites
.it10 websites
.ru9 websites
.ca7 websites
.co.uk7 websites
.co.jp6 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-19726

Top websites that are affected by CVE-2026-19726. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***********.com United States***,***
**************.de Germany***,***
****.lv Latvia***,***
*******.media Poland***,***
***********.eu Netherlands*,***,***
******.**.jp Japan*,***,***
****************.org United States*,***,***
********************.no Norway*,***,***
****.es Spain*,***,***
************.com United States*,***,***
See full domain list

FAQ

CVE-2026-19726 is Incorrect Authorization in Visualizer
A total of 425 websites have been identified as vulnerable to CVE-2026-19726, based on global website indexing conducted by WebTechSurvey.
The Visualizer is affected by the CVE-2026-19726 vulnerability.
Visualizer versions up to 4.0.7 are vulnerable to CVE-2026-19726.
CVE-2026-19726 is resolved in version 4.0.7 of Visualizer.