Description
WordPress Plugin Visualizer:Tables and Charts Manager for WordPress is prone to a deserialization vulnerability. Attackers can possibly exploit this issue to call files using a PHAR wrapper that will deserialize and call arbitrary PHP Objects that can be used to perform a variety of malicious actions, granted a POP chain is also present. WordPress Plugin Visualizer:Tables and Charts Manager for WordPress version 3.7.9 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.7.10 or latest
References
Related Vulnerabilities
WordPress Plugin Widgets for WooCommerce Products on Elementor Security Bypass (1.0.5)
WordPress Plugin FB Survey Pro 'id' Parameter SQL Injection (1.0)
PrestaShop Improper Privilege Management Vulnerability (CVE-2023-43663)
WordPress Plugin Slider Revolution Responsive Arbitrary File Upload (3.0.95)