WordPress Visualizer plugin before 3.3.1 contains a stored cross-site scripting vulnerability via /wp-json/visualizer/v1/update-chart WP-JSON API endpoint. An unauthenticated attacker can execute arbitrary JavaScript when an admin or other privileged user edits the chart via the admin dashboard.
id: CVE-2019-16931
info:
name: WordPress Visualizer <3.3.1 - Cross-Site Scripting
author: ritik
...