plugin

Portfolio Wp Vulnerabilities

3 known security issues reported for the Portfolio Wp WordPress plugin. Most recent disclosed Nov 19, 2025.

2 medium

Running Portfolio Wp on your site? Check whether your installed version is affected.

Scan your site free

Multiple Plugins and Themes <= (Various Versions) - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via lightGallery JavaScript Library

medium

Multiple plugins and/or themes for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled lightGallery library (<= 2.8.3) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with Contrib...

CVSS:
6.4
Affected:
up to 2.2.1
Fixed in:
2.2.2
Disclosed:
Nov 19, 2025

CVE-2025-5092 on NVD →

Portfolio Gallery, Product Catalog &#8211; Grid KIT Portfolio [portfolio-wp] < 2.1.0

unknown

[en] The Portfolio Gallery, Product Catalog WordPress plugin before 2.1.0 does not have authorisation and CSRF checks in various functions related to AJAX actions, allowing any authenticated users, such as subscriber, to call them. Due to the lack of sanitisation and escaping, it could also allows attackers to perform...

Affected:
up to 2.1.0
Fixed in:
2.1.0
Disclosed:
Apr 11, 2022

CVE-2021-25090 on NVD →

GridKit Portfolio <= 2.0.0 - Subscriber+ Stored Cross-Site Scripting

medium

The Portfolio Gallery, Product Catalog WordPress plugin before 2.1.0 does not have authorisation and CSRF checks in various functions related to AJAX actions, allowing any authenticated users, such as subscriber, to call them. Due to the lack of sanitisation and escaping, it could also allows attackers to perform Cross...

CVSS:
5.4
Affected:
up to 2.1.0
Fixed in:
2.1.0
Disclosed:
Mar 15, 2022

CVE-2021-25090 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database