plugin

Ez Portfolio Vulnerabilities

1 known security issue reported for the Ez Portfolio WordPress plugin. Most recent disclosed Feb 23, 2015.

1 medium

Running Ez Portfolio on your site? Check whether your installed version is affected.

Scan your site free

EZ Portfolio (Unmaintained) < 1.0.2 - Cross-Site Scripting

medium

The EZ Portfolio (Unmaintained) plugin for WordPress is vulnerable to Cross-Site Scripting via several parameters in versions before 1.0.2 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS:
6.1
Affected:
up to 1.0.2
Fixed in:
1.0.2
Disclosed:
Feb 23, 2015

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database