Extension WordPress
Vulnérabilités Portfolio by BestWebSoft – Work and Projects Presentation Plugin for WordPress
Cette page rassemble les failles publiées pour Portfolio by BestWebSoft – Work and Projects Presentation Plugin for WordPress, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Portfolio by BestWebSoft – Work and Projects Presentation Plugin for WordPress
2 fiches
Portfolio <= 2.58 – Authenticated (Author+) Stored Cross-Site Scripting
The Portfolio plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.58 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above,…
*-2.58
Non indiqué
22/09/2025
Portfolio by BestWebSoft < 2.4.0 – Reflected Cross-Site Scripting
The Portfolio by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘category’ parameter in versions before 2.4.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
[*, 2.4.0)
2.4.0
12/04/2017
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.