Graphina – Charts and Graphs For Elementor <= 3.1.12 - Missing Authorization
medium
The Graphina – Charts and Graphs For Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.1.12. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 3.1.12
- Fix:
- No patched version reported
- Disclosed:
- Jul 23, 2026
CVE-2026-65529 on NVD →
Graphina – Charts and Graphs For Elementor [graphina-elementor-charts-and-graphs] < 3.1.9
unknown
[en] The Graphina – Elementor Charts and Graphs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple chart widgets in all versions up to, and including, 3.1.8 due to insufficient input sanitization and output escaping on data attributes. This makes it possible for authenticated attackers, with...
- Affected:
- up to 3.1.9
- Fixed in:
- 3.1.9
- Disclosed:
- Nov 5, 2025
CVE-2025-11820 on NVD →
Graphina – Elementor Charts and Graphs <= 3.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Chart Widgets
medium
The Graphina – Elementor Charts and Graphs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple chart widgets in all versions up to, and including, 3.1.8 due to insufficient input sanitization and output escaping on data attributes. This makes it possible for authenticated attackers, with Cont...
- CVSS:
- 6.4
- Affected:
- up to 3.1.8
- Fixed in:
- 3.1.9
- Disclosed:
- Nov 4, 2025
CVE-2025-11820 on NVD →
Graphina - Elementor Charts and Graphs <= 3.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Graphina - Elementor Charts and Graphs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple chart widget parameters in version 3.1.3 and below. This is due to insufficient input sanitization and output escaping on user supplied attributes such as chart categories, titles, and tooltip setti...
- CVSS:
- 6.4
- Affected:
- up to 3.1.3
- Fixed in:
- 3.1.4
- Disclosed:
- Aug 14, 2025
CVE-2025-8867 on NVD →
Graphina <= 3.1.1 - Unauthenticated Local File Inclusion
high
The Graphina – Elementor Charts and Graphs plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.1.1. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be...
- CVSS:
- 8.1
- Affected:
- up to 3.1.1
- Fixed in:
- 3.1.2
- Disclosed:
- Jul 28, 2025
CVE-2025-23968 on NVD →
Graphina – Charts and Graphs For Elementor [graphina-elementor-charts-and-graphs] <= 3.1.1 (unfixed)
unknown
[en] Unrestricted Upload of File with Dangerous Type vulnerability in WPCenter AiBud WP allows Upload a Web Shell to a Web Server.This issue affects AiBud WP: from n/a through 1.8.5.
- Affected:
- up to 3.1.1
- Fix:
- No patched version reported
- Disclosed:
- Jul 3, 2025
CVE-2025-23968 on NVD →
Graphina <= 3.0.4 - Cross-Site Request Forgery to Local File Inclusion
high
The Graphina plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.0.4. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to update settings and include local files via a forged request granted t...
- CVSS:
- 7.5
- Affected:
- up to 3.0.4
- Fixed in:
- 3.0.5
- Disclosed:
- May 7, 2025
CVE-2025-47533 on NVD →
Graphina <= 3.0.4 - Missing Authorization
medium
The Graphina plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions like graphina_save_enabled_widgets() in versions up to, and including, 3.0.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify widgets.
- CVSS:
- 4.3
- Affected:
- up to 3.0.4
- Fixed in:
- 3.0.5
- Disclosed:
- May 7, 2025
CVE-2025-47480 on NVD →
Graphina – Charts and Graphs For Elementor [graphina-elementor-charts-and-graphs] < 3.0.5
unknown
[en] Missing Authorization vulnerability in Iqonic Design Graphina allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Graphina: from n/a through 3.0.4.
- Affected:
- up to 3.0.5
- Fixed in:
- 3.0.5
- Disclosed:
- May 7, 2025
CVE-2025-47480 on NVD →
Graphina – Charts and Graphs For Elementor [graphina-elementor-charts-and-graphs] < 3.0.5
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Iqonic Design Graphina allows PHP Local File Inclusion. This issue affects Graphina: from n/a through 3.0.4.
- Affected:
- up to 3.0.5
- Fixed in:
- 3.0.5
- Disclosed:
- May 7, 2025
CVE-2025-47533 on NVD →
Graphina – Charts and Graphs For Elementor [graphina-elementor-charts-and-graphs] < 2.0.0
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Iqonic Design Graphina allows Stored XSS.This issue affects Graphina: from n/a through 1.8.10.
- Affected:
- up to 2.0.0
- Fixed in:
- 2.0.0
- Disclosed:
- Aug 12, 2024
CVE-2024-43124 on NVD →
Graphina <= 1.8.10 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Graphina plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.8.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that w...
- CVSS:
- 6.4
- Affected:
- up to 1.8.10
- Fixed in:
- 2.0.0
- Disclosed:
- Aug 7, 2024
CVE-2024-43124 on NVD →
Graphina – Elementor Charts and Graphs <= 1.8.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets
medium
The Graphina – Elementor Charts and Graphs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 1.8.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with c...
- CVSS:
- 6.4
- Affected:
- up to 1.8.9
- Fixed in:
- 1.8.10
- Disclosed:
- May 10, 2024
CVE-2024-4574 on NVD →
Graphina – Charts and Graphs For Elementor [graphina-elementor-charts-and-graphs] < 1.8.10
unknown
[en] The Graphina – Elementor Charts and Graphs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 1.8.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, w...
- Affected:
- up to 1.8.10
- Fixed in:
- 1.8.10
- Disclosed:
- May 10, 2024
CVE-2024-4574 on NVD →
Graphina – Charts and Graphs For Elementor [graphina-elementor-charts-and-graphs] < 3.1.4
unknown
- Affected:
- up to 3.1.4
- Fixed in:
- 3.1.4
CVE-2025-8867 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database