Stored Cross-Site Scripting Vulnerability in Power Charts Lite Plugin for WordPress
CVE-2026-4011

6.4MEDIUM

What is CVE-2026-4011?

The Power Charts Lite plugin for WordPress is affected by a Stored Cross-Site Scripting vulnerability caused by insufficient input sanitization in the 'id' parameter of the [pc] shortcode. The vulnerability allows authenticated users with Contributor-level access and higher to exploit the flaw by injecting malicious scripts. The 'id' attribute can be manipulated as it is directly concatenated into an HTML div element's class attribute without proper escaping, enabling the execution of arbitrary scripts when users visit compromised pages.

Affected Version(s)

Power Charts – Responsive Beautiful Charts & Graphs 0 <= 0.1.0

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Muhammad Yudha - DJ
.