First published: Fri Feb 28 2025(Updated: )
The WordPress Portfolio Builder – Portfolio Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'pfhub_portfolio' and 'pfhub_portfolio_portfolio' shortcodes in all versions up to, and including, 1.1.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Portfolio Gallery | <=1.1.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-1757 is classified as a medium severity vulnerability due to the potential for stored cross-site scripting attacks.
To remediate CVE-2025-1757, update the WordPress Portfolio Builder – Portfolio Gallery plugin to the latest version beyond 1.1.7.
Stored Cross-Site Scripting in CVE-2025-1757 allows attackers to inject malicious scripts into the user's browser when the affected shortcode is executed.
Users of the WordPress Portfolio Builder – Portfolio Gallery plugin in versions up to and including 1.1.7 are affected by CVE-2025-1757.
The affected shortcodes in CVE-2025-1757 are 'pfhub_portfolio' and 'pfhub_portfolio_portfolio'.