Extension WordPress
Vulnérabilités PowerFolio – Portfolio & Image Gallery for Elementor
Cette page rassemble les failles publiées pour PowerFolio – Portfolio & Image Gallery for Elementor, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de PowerFolio – Portfolio & Image Gallery for Elementor
5 fiches
PowerFolio <= 3.2.1 – Authenticated (Contributor+) Stored Cross-Site Scripting
The PowerFolio plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,…
*-3.2.1
3.2.2
22/09/2025
Portfolio for Elementor & Image Gallery | PowerFolio <= 3.2.0 – Authenticated (Contributor+) Stored Cross-Site Scripting via Custom JS
The Portfolio for Elementor & Image Gallery | PowerFolio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom JS Attributes of Plugin's widgets in all versions up to, and including, 3.2.0 due to insufficient input…
*-3.2.0
3.2.1
03/07/2025
Post Grid, Image Gallery & Portfolio for Elementor | PowerFolio <= 3.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode
The Portfolio & Image Gallery for WordPress | PowerFolio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 3.1 due to insufficient input sanitization and output escaping…
*-3.1
3.1.1
16/01/2024
Portfolio for Elementor <= 2.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The Portfolio for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to, and including, 2.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes…
*-2.3
2.3.1
03/01/2023
Freemius SDK <= 2.4.2 – Missing Authorization Checks
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions…
[*, 2.1.7)
2.1.7
04/03/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.