CVE-2024-3750 is a critical vulnerability affecting the Visualizer: Tables and Charts Manager plugin for WordPress, versions up to and including 3.10.15. This flaw stems from a missing capability check in the getQueryData() function, allowing authenticated attackers with subscriber-level access to execute arbitrary SQL queries. With a CVSS score of 8.8 (HIGH), this vulnerability enables privilege escalation and unauthorized data modification or retrieval. Currently, there is no public exploit code available, nor is there evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Themeisle | Visualizer: Tables And Charts Manager For WordPress | >= 0, <= 3.10.15CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.