CVE-2019-16932: Themeisle Visualizer

Critical severity, CVSS 10.0. EPSS: 39.1% chance of exploitation in the next 30 days.

A blind SSRF vulnerability exists in the Visualizer plugin before 3.3.1 for WordPress via wp-json/visualizer/v1/upload-data.

Affected products

  • Themeisle Visualizer: before 3.3.1 (fixed in 3.3.1)

Published 2019-09-30. Last modified 2026-06-17.