Simple Org Chart
Simple Org Chart has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2023; all 2 are fixed as of September 2026. Their average CVSS score is 4.8, and the most serious one scores 5.3 out of 10. 2023 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (50%). Other recurring categories include Missing Authorization.
Every one of the 2 issues recorded for Simple Org Chart has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. Simple Org Chart is installed on roughly 900 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2023-40603Simple Org Chart <= 2.3.4 - Missing Authorization
Read the full analysisVulnerability Records

Simple Org Chart
Author
G Matta
This plugin allows you to seamlessly setup a hierarchical based organisation chart, otherwise known as an Org Chart, for use in your website. We have integrated drag and drop features to ensure the process is intuitive and fast. The Chart is able to display a Gravatar image and user’s display name. In the future we are aiming to add a template system which will allow more information to be displayed. Now chart JSON can be accessed using endpoint. Endpoint for JSON. {domain.com}/wp-json/org_chart/json JSON format can be updated using “parseJSON” function in index.php . Its a pluggable function. WP Org Chart Pro is released. * Responsive * Buddypress Support * Multiple Charts * JSON Access * Custom Departments * Simple user management * Template system for custom design * Hooks and Filters for custom fields * Print Chart * Replace Top Level user without reset chart Demo Credits: @wesnolte : https://github.com/wesnolte/jOrgChart
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C