Stored Cross-Site Scripting Vulnerability in Power Charts Lite Plugin for WordPress
CVE-2026-4011
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 15 April 2026
What is CVE-2026-4011?
The Power Charts Lite plugin for WordPress is affected by a Stored Cross-Site Scripting vulnerability caused by insufficient input sanitization in the 'id' parameter of the [pc] shortcode. The vulnerability allows authenticated users with Contributor-level access and higher to exploit the flaw by injecting malicious scripts. The 'id' attribute can be manipulated as it is directly concatenated into an HTML div element's class attribute without proper escaping, enabling the execution of arbitrary scripts when users visit compromised pages.
Affected Version(s)
Power Charts β Responsive Beautiful Charts & Graphs 0 <= 0.1.0