First published: Thu Jan 16 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tushar Patel Easy Portfolio allows Stored XSS.This issue affects Easy Portfolio: from n/a through 1.3.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Tushar Patel Easy Portfolio | <=1.3 | |
WordPress Easy Portfolio | <=1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-23796 is classified as a medium severity vulnerability due to its potential to allow Stored Cross-site Scripting (XSS) attacks.
To fix CVE-2025-23796, update the Easy Portfolio plugin to version 1.4 or later, which addresses the XSS vulnerability.
The potential impacts of CVE-2025-23796 include unauthorized access to sensitive user data and the ability for an attacker to execute malicious scripts in the context of the user's browser.
CVE-2025-23796 affects versions of Easy Portfolio from n/a through 1.3.
The vendor for CVE-2025-23796 is Tushar Patel, the developer of the Easy Portfolio plugin.