Title: SQL Injection vulnerability
Last modified: July 28, 2026

---

# SQL Injection vulnerability

 *  Resolved [Ken Gagne](https://wordpress.org/support/users/kgagne/)
 * (@kgagne)
 * [2 weeks, 4 days ago](https://wordpress.org/support/topic/sql-injection-vulnerability-20/)
 * Jetpack informed me of vulnerability `CVE-2026-65526` affecting v4.0.6 and earlier
   of this plugin:
 * > The Visualizer – Tables & Charts Manager with Built-in AI Generator plugin 
   > for WordPress is vulnerable to SQL Injection in versions up to, and including,
   > 4.0.6 due to insufficient escaping on the user supplied parameter and lack 
   > of sufficient preparation on the existing SQL query. This makes it possible
   > for authenticated attackers, with contributor-level access and above, to append
   > additional SQL queries into already existing queries that can be used to extract
   > sensitive information from the database.
 * I’m eager for a fix! 🙏
 * The page I need help with: _[[log in](https://login.wordpress.org/?redirect_to=https%3A%2F%2Fwordpress.org%2Fsupport%2Ftopic%2Fsql-injection-vulnerability-20%2F%3Foutput_format%3Dmd&locale=en_US)
   to see the link]_

Viewing 3 replies - 1 through 3 (of 3 total)

 *  [Buddy](https://wordpress.org/support/users/friendswp/)
 * (@friendswp)
 * [2 weeks, 4 days ago](https://wordpress.org/support/topic/sql-injection-vulnerability-20/#post-18976965)
 * Hi,
 * Thank you for bringing this to our attention.
 * This vulnerability was reported to us through Patchstack in May. We investigated
   it, implemented a fix, and released the patch in Visualizer version 4.0.2 on 
   May 19. The fix was also reviewed and approved by Patchstack, as shown in this
   screenshot:
 * [https://cleanshot.com/share/lgmHmlsk](https://cleanshot.com/share/lgmHmlsk)
 * It appears that Patchstack’s vulnerability database was not updated afterward
   and still incorrectly lists the issue as unpatched and affecting versions up 
   to 4.0.6. This outdated entry is likely what triggered the Jetpack warning.
 * We have already contacted Patchstack and asked them to verify and correct the
   database entry. Based on our investigation and the approved fix, version 4.0.6
   is not affected by this vulnerability.
 * Please make sure you are running the latest version of Visualizer. No further
   action should be required.
 * Thank you again for reporting this, and we apologize for the confusion caused
   by the incorrect database status.
 *  Thread Starter [Ken Gagne](https://wordpress.org/support/users/kgagne/)
 * (@kgagne)
 * [2 weeks, 3 days ago](https://wordpress.org/support/topic/sql-injection-vulnerability-20/#post-18977512)
 * Thank you for the swift response, and sorry for the false alarm!
 *  [jalorod](https://wordpress.org/support/users/jalorod/)
 * (@jalorod)
 * [2 weeks, 2 days ago](https://wordpress.org/support/topic/sql-injection-vulnerability-20/#post-18978764)
 * Thank you for info, I had the same problem.
 * Regards,

Viewing 3 replies - 1 through 3 (of 3 total)

You must be [logged in](https://login.wordpress.org/?redirect_to=https%3A%2F%2Fwordpress.org%2Fsupport%2Ftopic%2Fsql-injection-vulnerability-20%2F%3Foutput_format%3Dmd&locale=en_US)
to reply to this topic.

 * ![](https://ps.w.org/visualizer/assets/icon-256x256.gif?rev=3084574)
 * [Visualizer – Tables & Charts Manager with Built-in AI Generator](https://wordpress.org/plugins/visualizer/)
 * [Frequently Asked Questions](https://wordpress.org/plugins/visualizer/#faq)
 * [Support Threads](https://wordpress.org/support/plugin/visualizer/)
 * [Active Topics](https://wordpress.org/support/plugin/visualizer/active/)
 * [Unresolved Topics](https://wordpress.org/support/plugin/visualizer/unresolved/)
 * [Reviews](https://wordpress.org/support/plugin/visualizer/reviews/)

 * 4 replies
 * 3 participants
 * Last reply from: [jalorod](https://wordpress.org/support/users/jalorod/)
 * Last activity: [2 weeks, 2 days ago](https://wordpress.org/support/topic/sql-injection-vulnerability-20/#post-18978764)
 * Status: resolved