plugin

Themify Portfolio Post Vulnerabilities

13 known security issues reported for the Themify Portfolio Post WordPress plugin. Most recent disclosed Dec 15, 2025.

6 medium

Running Themify Portfolio Post on your site? Check whether your installed version is affected.

Scan your site free

Themify Portfolio Post <= 1.3.0 - Authenticated (Author+) Stored Cross-Site Scripting

medium

The Themify Portfolio Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in page...

CVSS:
6.4
Affected:
up to 1.3.0
Fixed in:
1.3.1
Disclosed:
Dec 15, 2025

CVE-2025-67533 on NVD →

Themify Portfolio Post [themify-portfolio-post] <= 1.3.0 (unfixed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themifyme Themify Portfolio Post themify-portfolio-post allows Stored XSS.This issue affects Themify Portfolio Post: from n/a through <= 1.3.0.

Affected:
up to 1.3.0
Fix:
No patched version reported
Disclosed:
Dec 9, 2025

CVE-2025-67533 on NVD →

Themify Portfolio Post [themify-portfolio-post] < 1.2.5

unknown

[en] Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in Themify Themify Portfolio Post plugin <= 1.2.4 versions.

Affected:
up to 1.2.5
Fixed in:
1.2.5
Disclosed:
May 10, 2023

CVE-2022-32970 on NVD →

Themify Portfolio Post <= 1.2.4 - Authenticated (Editor+) Stored Cross-Site Scripting

medium

The Themify Portfolio Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level access and above, to inject arbitrary web scripts in page...

CVSS:
5.5
Affected:
up to 1.2.4
Fixed in:
1.2.5
Disclosed:
Apr 18, 2023

CVE-2022-32970 on NVD →

Themify Portfolio Post [themify-portfolio-post] < 1.2.2

unknown

[en] Themify Portfolio Post WordPress plugin before 1.2.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

Affected:
up to 1.2.2
Fixed in:
1.2.2
Disclosed:
Feb 13, 2023

CVE-2023-0362 on NVD →

Themify Portfolio Post <= 1.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The Themify Portfolio Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor l...

CVSS:
6.4
Affected:
up to 1.2.1
Fixed in:
1.2.2
Disclosed:
Jan 19, 2023

CVE-2023-0362 on NVD →

Themify Portfolio Post [themify-portfolio-post] < 1.2.1

unknown

[en] Themify Portfolio Post WordPress plugin before 1.2.1 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks, which could be used against high privileged users...

Affected:
up to 1.2.1
Fixed in:
1.2.1
Disclosed:
Jan 16, 2023

CVE-2022-4464 on NVD →

Themify Portfolio Post <= 1.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The Themify Portfolio Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to, and including, 1.2.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor lev...

CVSS:
6.4
Affected:
up to 1.2.0
Fixed in:
1.2.1
Disclosed:
Dec 23, 2022

CVE-2022-4464 on NVD →

Themify Portfolio Post [themify-portfolio-post] < 1.1.7

unknown

[en] Themify Portfolio Post WordPress plugin before 1.1.7 does not sanitise and escape the num_of_pages parameter before outputting it back the response of the themify_create_popup_page_pagination AJAX action (available to any authenticated user), leading to a Reflected Cross-Site Scripting

Affected:
up to 1.1.7
Fixed in:
1.1.7
Disclosed:
Feb 14, 2022

CVE-2022-0200 on NVD →

Themify Portfolio Post <= 1.1.6 - Reflected Cross-Site Scripting

medium

Themify Portfolio Post WordPress plugin before 1.1.7 does not sanitise and escape the num_of_pages parameter before outputting it back the response of the themify_create_popup_page_pagination AJAX action (available to any authenticated user), leading to a Reflected Cross-Site Scripting

CVSS:
5.4
Affected:
up to 1.1.6
Fixed in:
1.1.7
Disclosed:
Jan 14, 2022

CVE-2022-0200 on NVD →

Themify Portfolio Post [themify-portfolio-post] < 1.1.6

unknown

[en] Unvalidated input and lack of output encoding in the Themify Portfolio Post WordPress plugin, versions before 1.1.6, lead to Stored Cross-Site Scripting (XSS) vulnerabilities allowing low-privileged users (Contributor+) to inject arbitrary JavaScript code or HTML in posts where the Themify Custom Panel is embedded...

Affected:
up to 1.1.6
Fixed in:
1.1.6
Disclosed:
Mar 18, 2021

CVE-2021-24129 on NVD →

Themify Portfolio Post <= 1.1.5 - Authenticated Stored Cross-Site Scripting

medium

Unvalidated input and lack of output encoding in the Themify Portfolio Post WordPress plugin, versions before 1.1.6, lead to Stored Cross-Site Scripting (XSS) vulnerabilities allowing low-privileged users (Contributor+) to inject arbitrary JavaScript code or HTML in posts where the Themify Custom Panel is embedded, whi...

CVSS:
5.4
Affected:
up to 1.1.5
Fixed in:
1.1.6
Disclosed:
Dec 4, 2020

CVE-2021-24129 on NVD →

Themify Portfolio Post [themify-portfolio-post] < 1.1.6

unknown

Authenticated Stored Cross-Site Scripting (XSS) vulnerability found by Nguyen Anh Tien (SunCSR) in WordPress Themify Portfolio Post plugin (versions <= 1.1.5).

Affected:
up to 1.1.6
Fixed in:
1.1.6
Disclosed:
Dec 4, 2020

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database