plugin

Organization Chart Vulnerabilities

12 known security issues reported for the Organization Chart WordPress plugin. Most recent disclosed May 25, 2026.

1 high 5 medium

Running Organization Chart on your site? Check whether your installed version is affected.

Scan your site free

Organization chart <= 1.7.5 - Cross-Site Request Forgery

medium

The Organization chart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.5. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they ca...

CVSS:
4.3
Affected:
up to 1.7.5
Fixed in:
1.7.6
Disclosed:
May 25, 2026

CVE-2026-24597 on NVD →

Organization chart <= 1.5.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting via title_input and node_description Parameters

medium

The Organization chart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title_input’ and 'node_description' parameter in all versions up to, and including, 1.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-leve...

CVSS:
4.9
Affected:
up to 1.5.0
Fixed in:
1.5.1
Disclosed:
Aug 7, 2024

CVE-2024-7355 on NVD →

Organization chart [organization-chart] < 1.5.1

unknown

[en] The Organization chart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title_input’ and 'node_description' parameter in all versions up to, and including, 1.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber...

Affected:
up to 1.5.1
Fixed in:
1.5.1
Disclosed:
Aug 7, 2024

CVE-2024-7355 on NVD →

Organization chart [organization-chart] < 1.4.5

unknown

[en] Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPdevart Organization chart plugin <= 1.4.4 versions.

Affected:
up to 1.4.5
Fixed in:
1.4.5
Disclosed:
Apr 6, 2023

CVE-2023-24387 on NVD →

Organization chart [organization-chart] < 1.4.5

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in WpDevArt Organization chart <= 1.4.4 versions.

Affected:
up to 1.4.5
Fixed in:
1.4.5
Disclosed:
Feb 23, 2023

CVE-2023-24384 on NVD →

Organization chart <= 1.4.4 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Organization chart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 1.4.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject ar...

CVSS:
4.4
Affected:
up to 1.4.5
Fixed in:
1.4.5
Disclosed:
Jan 27, 2023

CVE-2023-24387 on NVD →

Organization chart <= 1.4.4 - Cross-Site Request Forgery

medium

The Organization chart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.4. This is due to missing or incorrect nonce validation saving, updating, duplicating and deleting popup themes. This makes it possible for unauthenticated attackers to invoke those actions via...

CVSS:
4.3
Affected:
up to 1.4.4
Fixed in:
1.4.5
Disclosed:
Jan 27, 2023

CVE-2023-24384 on NVD →

Organization chart <= 1.4.1 - Cross-Site Request Forgery

high

The Organization chart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.1. This is due to missing or incorrect nonce validation on the post_page_content function. This makes it possible for unauthenticated attackers to invoke this function, via forged request grante...

CVSS:
8.8
Affected:
1.4.1 – 1.4.1
Fixed in:
1.4.2
Disclosed:
Nov 26, 2022

Organization chart <= 1.4.1 - Missing Authorization

medium

The Organization chart plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the post_page_content function in versions up to, and including, 1.4.1. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function.

CVSS:
4.3
Affected:
up to 1.4.1
Fixed in:
1.4.2
Disclosed:
Nov 26, 2022

CVE-2022-45844 on NVD →

Organization chart [organization-chart] < 1.4.3

unknown

The Organization chart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.1. This is due to missing or incorrect nonce validation on the post_page_content function. This makes it possible for unauthenticated attackers to invoke this function, via forged request grante...

Affected:
up to 1.4.3
Fixed in:
1.4.3
Disclosed:
Nov 26, 2022

Organization chart [organization-chart] < 1.4.2

unknown

The Organization chart plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the post_page_content function in versions up to, and including, 1.4.1. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function.

Affected:
up to 1.4.2
Fixed in:
1.4.2
Disclosed:
Nov 26, 2022

Organization chart [organization-chart] < 1.4.2

unknown

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Affected:
up to 1.4.2
Fixed in:
1.4.2

CVE-2022-45844 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database