Chartify – WordPress Chart Plugin [chart-builder] <= 3.6.3 (unfixed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Ays Pro Chartify chart-builder allows Cross Site Request Forgery.This issue affects Chartify: from n/a through <= 3.6.3.
- Affected:
- up to 3.6.3
- Fix:
- No patched version reported
- Disclosed:
- Dec 9, 2025
CVE-2025-66529 on NVD →
Chartify <= 3.6.3 - Cross-Site Request Forgery
medium
The Chartify – WordPress Chart Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.3. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action granted they can...
- CVSS:
- 4.3
- Affected:
- up to 3.6.3
- Fixed in:
- 3.6.4
- Disclosed:
- Dec 3, 2025
CVE-2025-66529 on NVD →
Chartify – WordPress Chart Plugin [chart-builder] < 3.6.0
unknown
[en] The Chartify – WordPress Chart Plugin for WordPress is vulnerable to Missing Authentication for Critical Function in all versions up to, and including, 3.5.9. This is due to the plugin registering an unauthenticated AJAX action that dispatches to admin-class methods based on a request parameter, without any nonce...
- Affected:
- up to 3.6.0
- Fixed in:
- 3.6.0
- Disclosed:
- Oct 8, 2025
CVE-2025-11171 on NVD →
Chartify – WordPress Chart Plugin <= 3.5.9 - Missing Authentication for Administrative Function
medium
The Chartify – WordPress Chart Plugin for WordPress is vulnerable to Missing Authentication for Critical Function in all versions up to, and including, 3.5.9. This is due to the plugin registering an unauthenticated AJAX action that dispatches to admin-class methods based on a request parameter, without any nonce or ca...
- CVSS:
- 5.3
- Affected:
- up to 3.5.9
- Fixed in:
- 3.6.0
- Disclosed:
- Oct 7, 2025
CVE-2025-11171 on NVD →
Chartify – WordPress Chart Plugin [chart-builder] < 3.5.4
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Ays Pro Chartify allows Cross Site Request Forgery. This issue affects Chartify: from n/a through 3.5.3.
- Affected:
- up to 3.5.4
- Fixed in:
- 3.5.4
- Disclosed:
- Aug 14, 2025
CVE-2025-54673 on NVD →
Chartify <= 3.5.3 - Cross-Site Request Forgery
medium
The Chartify – WordPress Chart Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.5.3. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action granted they can...
- CVSS:
- 4.3
- Affected:
- up to 3.5.3
- Fixed in:
- 3.5.4
- Disclosed:
- Jul 30, 2025
CVE-2025-54673 on NVD →
Chartify <= 3.1.7 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Chartify plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.1.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages that...
- CVSS:
- 4.4
- Affected:
- up to 3.1.7
- Fixed in:
- 3.1.9
- Disclosed:
- Mar 27, 2025
CVE-2025-30904 on NVD →
Chartify – WordPress Chart Plugin [chart-builder] < 3.1.9
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Chartify allows Stored XSS. This issue affects Chartify: from n/a through 3.1.7.
- Affected:
- up to 3.1.9
- Fixed in:
- 3.1.9
- Disclosed:
- Mar 27, 2025
CVE-2025-30904 on NVD →
Chartify – WordPress Chart Plugin [chart-builder] < 2.9.6
unknown
[en] The Chartify – WordPress Chart Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.9.5 via the 'source' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code...
- Affected:
- up to 2.9.6
- Fixed in:
- 2.9.6
- Disclosed:
- Nov 14, 2024
CVE-2024-10571 on NVD →
Chartify – WordPress Chart Plugin <= 2.9.5 - Unauthenticated Local File Inclusion via source
critical
The Chartify – WordPress Chart Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.9.5 via the 'source' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in th...
- CVSS:
- 9.8
- Affected:
- up to 2.9.5
- Fixed in:
- 2.9.6
- Disclosed:
- Nov 13, 2024
CVE-2024-10571 on NVD →
Chartify – WordPress Chart Plugin [chart-builder] < 2.7.7
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Chart Builder Team Chartify allows Reflected XSS.This issue affects Chartify: from n/a through 2.7.6.
- Affected:
- up to 2.7.7
- Fixed in:
- 2.7.7
- Disclosed:
- Oct 6, 2024
CVE-2024-47347 on NVD →
Chartify <= 2.7.6 - Reflected Cross-Site Scripting
medium
The Chartify plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.7.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick...
- CVSS:
- 6.1
- Affected:
- up to 2.7.6
- Fixed in:
- 2.7.7
- Disclosed:
- Sep 27, 2024
CVE-2024-47347 on NVD →
Chartify – WordPress Chart Plugin [chart-builder] < 2.0.7
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chart Builder Team Chartify – WordPress Chart Plugin allows Stored XSS.This issue affects Chartify – WordPress Chart Plugin: from n/a through 2.0.6.
- Affected:
- up to 2.0.7
- Fixed in:
- 2.0.7
- Disclosed:
- Feb 12, 2024
CVE-2023-47526 on NVD →
Chartify <= 2.0.6 - Authenticated(Administrator+) Stored Cross-Site Scripting
medium
The Chartify – WordPress Chart Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.0.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and...
- CVSS:
- 4.4
- Affected:
- up to 2.0.6
- Fixed in:
- 2.0.7
- Disclosed:
- Jan 31, 2024
CVE-2023-47526 on NVD →
Chartify – WordPress Chart Plugin [chart-builder] < 1.9.7
unknown
Update the WordPress Chartify plugin to the latest available version (at least 1.9.7).
Unknown discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Chartify Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads in...
- Affected:
- up to 1.9.7
- Fixed in:
- 1.9.7
- Disclosed:
- Nov 30, 2023
Chart Builder <= 1.9.6 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Best Chart Plugin – Chartify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.9.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above...
- CVSS:
- 4.4
- Affected:
- up to 1.9.6
- Fixed in:
- 1.9.7
- Disclosed:
- Nov 28, 2023
Chartify – WordPress Chart Plugin [chart-builder] < 1.9.7
unknown
The Best Chart Plugin – Chartify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.9.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above...
- Affected:
- up to 1.9.7
- Fixed in:
- 1.9.7
- Disclosed:
- Nov 28, 2023
Chartify – WordPress Chart Plugin [chart-builder] < 1.9.7
unknown
The plugin does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
- Affected:
- up to 1.9.7
- Fixed in:
- 1.9.7
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database