M Chart

M Chart has one disclosed vulnerability in the WordSec catalog, all reported in 2023; it is fixed as of September 2026. Their average CVSS score is 5.4, and the most serious one scores 5.4 out of 10.

The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).

The one issue recorded for M Chart has a vendor fix available, so running the current release closes it.

All of these findings were reported by thiennv. M Chart is installed on roughly 3,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

Strategic Overview

Avg CVSSMedium
5.4/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all M Chart vulnerabilities before they are exploited.

Highest severity on recordCVSS 5.4CVE-2023-23892

M Chart <= 1.9.4 - Authenticated (Contributor+) Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

1 records
Showing 1–1 of 1 reports
M Chart banner
Latestv2.3.2
4.9(28)
98/100
Last Updated
2026-09-06 (7d ago)
Active Installs
3,000+
Downloads
124,147
Requires WP
6.6+
Requires PHP
8.1+
Tested up to
WP 7.1
Created
2015-04-27 (12y ago)

Manage your data in a spreadsheet or with an accessible CSV import, display it as any of 19 chart types using the bundled Chart.js library, and embed it anywhere with a shortcode or the block editor. Features: 19 chart types — line, spline, area, column, stacked column, bar, stacked bar, pie, doughnut, scatter, bubble, radar, radar area, polar, treemap, boxplot, violin, venn, and euler Two ways to enter data — a spreadsheet with multi-sheet support, or a fully keyboard-accessible CSV import with configurable delimiters Live preview — the chart redraws instantly as you edit your data and settings, so you can see exactly what you’ll get before publishing Multiple output formats — render as a live interactive chart, a static image, or a plain HTML data table, all from the same chart Automatic image generation — every chart is automatically saved as a PNG image (no extra software or external service required) Images have a configurable width and 1x–4x quality multiplier Perfect for RSS feeds, emails, AMP pages, and anywhere JavaScript doesn’t work Flexible embedding — shortcode, block editor block, or iframe for embedding on other sites Accessibility (WCAG 2.1 AA) — every front-end chart includes a hidden data table for screen readers Themes — bundled Chart.js themes, switchable per install, including a Color Blind Safe palette Responsive and fast — charts size to their container, defer rendering until scrolled into view, and lazy-load in the block editor Localization — locale-aware number formatting, plus full translation support Per-chart customization — title/subtitle, axis titles and units, forced axis minimum, legend and shared-tooltip toggles, data-point labels, source attribution, and “color per data point” Note: M Chart Pro is a premium add-on that adds some additional features. Support for it was added in version 2.2. For a detailed explanation of why M Chart Pro exists and my plans going forward, read Why M Chart Pro. The short version: M Chart will continue to be supported and developed. I’ve been working on this plugin and providing it for free for over 10 years now, and that won’t change. That support and development will continue to match my original scope for the plugin: an efficient, easy-to-use UI for managing datasets and displaying them as charts, and nothing more. Because my time for M Chart is limited, I’ve intentionally not added some features that have been requested over the years. Not because they were bad ideas, but because I couldn’t give them the time they deserve. M Chart Pro is where I add those out-of-scope features. Its yearly subscription fee will hopefully give me the financial stability to devote my time more fully to M Chart overall. Note: The M Chart Highcharts Library is deprecated and will not receive further updates. Chart.js now matches Highcharts feature-for-feature, supports additional chart types, works with M Chart Pro, is faster, and doesn’t require an expensive commercial license. If you have Highcharts charts, M Chart offers a one-click migration to Chart.js. Accessibility: M Chart targets WCAG 2.1 Level AA. Charts on the front end include a hidden data table for screen-reader users, and a Color Blind Safe theme is bundled. Screen-reader users entering chart data should use the CSV Import feature: the spreadsheet has partial keyboard support, but CSV import is fully accessible. For full documentation, see the Documentation. To contribute, report issues, or make feature requests, use GitHub.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C