Organization chart <= 1.7.5 - Cross-Site Request Forgery
medium
The Organization chart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.5. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they ca...
- CVSS:
- 4.3
- Affected:
- up to 1.7.5
- Fixed in:
- 1.7.6
- Disclosed:
- May 25, 2026
CVE-2026-24597 on NVD →
Organization chart <= 1.5.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting via title_input and node_description Parameters
medium
The Organization chart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title_input’ and 'node_description' parameter in all versions up to, and including, 1.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-leve...
- CVSS:
- 4.9
- Affected:
- up to 1.5.0
- Fixed in:
- 1.5.1
- Disclosed:
- Aug 7, 2024
CVE-2024-7355 on NVD →
Organization chart [organization-chart] < 1.5.1
unknown
[en] The Organization chart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title_input’ and 'node_description' parameter in all versions up to, and including, 1.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber...
- Affected:
- up to 1.5.1
- Fixed in:
- 1.5.1
- Disclosed:
- Aug 7, 2024
CVE-2024-7355 on NVD →
Organization chart [organization-chart] < 1.4.5
unknown
[en] Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPdevart Organization chart plugin <= 1.4.4 versions.
- Affected:
- up to 1.4.5
- Fixed in:
- 1.4.5
- Disclosed:
- Apr 6, 2023
CVE-2023-24387 on NVD →
Organization chart [organization-chart] < 1.4.5
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in WpDevArt Organization chart <= 1.4.4 versions.
- Affected:
- up to 1.4.5
- Fixed in:
- 1.4.5
- Disclosed:
- Feb 23, 2023
CVE-2023-24384 on NVD →
Organization chart <= 1.4.4 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Organization chart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 1.4.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject ar...
- CVSS:
- 4.4
- Affected:
- up to 1.4.5
- Fixed in:
- 1.4.5
- Disclosed:
- Jan 27, 2023
CVE-2023-24387 on NVD →
Organization chart <= 1.4.4 - Cross-Site Request Forgery
medium
The Organization chart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.4. This is due to missing or incorrect nonce validation saving, updating, duplicating and deleting popup themes. This makes it possible for unauthenticated attackers to invoke those actions via...
- CVSS:
- 4.3
- Affected:
- up to 1.4.4
- Fixed in:
- 1.4.5
- Disclosed:
- Jan 27, 2023
CVE-2023-24384 on NVD →
Organization chart <= 1.4.1 - Cross-Site Request Forgery
high
The Organization chart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.1. This is due to missing or incorrect nonce validation on the post_page_content function. This makes it possible for unauthenticated attackers to invoke this function, via forged request grante...
- CVSS:
- 8.8
- Affected:
- 1.4.1 – 1.4.1
- Fixed in:
- 1.4.2
- Disclosed:
- Nov 26, 2022
Organization chart <= 1.4.1 - Missing Authorization
medium
The Organization chart plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the post_page_content function in versions up to, and including, 1.4.1. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function.
- CVSS:
- 4.3
- Affected:
- up to 1.4.1
- Fixed in:
- 1.4.2
- Disclosed:
- Nov 26, 2022
CVE-2022-45844 on NVD →
Organization chart [organization-chart] < 1.4.3
unknown
The Organization chart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.1. This is due to missing or incorrect nonce validation on the post_page_content function. This makes it possible for unauthenticated attackers to invoke this function, via forged request grante...
- Affected:
- up to 1.4.3
- Fixed in:
- 1.4.3
- Disclosed:
- Nov 26, 2022
Organization chart [organization-chart] < 1.4.2
unknown
The Organization chart plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the post_page_content function in versions up to, and including, 1.4.1. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function.
- Affected:
- up to 1.4.2
- Fixed in:
- 1.4.2
- Disclosed:
- Nov 26, 2022
Organization chart [organization-chart] < 1.4.2
unknown
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
- Affected:
- up to 1.4.2
- Fixed in:
- 1.4.2
CVE-2022-45844 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database