Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dinamiko DPortfolio dportfolio allows Reflected XSS.This issue affects DPortfolio: from n/a through <= 2.0.
Published: 2025-01-31
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper neutralization of input during web page generation that permits reflected cross‑site scripting in the DPortfolio plugin. An attacker can craft URLs containing malicious script payloads that the plugin displays without sanitization. If the victim’s browser executes the injected script, the attacker could steal session cookies, tamper with page content, or exfiltrate data. Based on the description, it is inferred that the impact is confined to the victim’s browser context and does not involve server‑side compromise.

Affected Systems

The affected product is the DPortfolio plugin for WordPress developed by dinamiko. All versions up to and including 2.0 are vulnerable; any installation using a pre‑2.1 release is at risk.

Risk and Exploitability

The CVSS score of 7.1 places this flaw in the high‑severity range. The EPSS score of less than 1% indicates a low probability of exploitation today, though the plugin accepts unsanitized parameters without authentication, so a crafted URL can trigger the XSS. The flaw is not listed in CISA KEV, indicating no known large‑scale exploitation. The likely attack vector is a reflected XSS triggered by a malicious link that a site visitor clicks or is redirected to, allowing the attacker to execute code in the victim’s browser.

Generated by OpenCVE AI on May 2, 2026 at 05:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the DPortfolio plugin to a version newer than 2.0
  • If updating is not feasible immediately, disable the plugin until a patch is available
  • Use a web application firewall or WordPress security plugin to filter or sanitize untrusted URL parameters reflected by the plugin

Generated by OpenCVE AI on May 2, 2026 at 05:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3746 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Emili Castells DPortfolio allows Reflected XSS. This issue affects DPortfolio: from n/a through 2.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Emili Castells DPortfolio allows Reflected XSS. This issue affects DPortfolio: from n/a through 2.0. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dinamiko DPortfolio dportfolio allows Reflected XSS.This issue affects DPortfolio: from n/a through <= 2.0.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Fri, 11 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00035}

epss

{'score': 0.00045}


Mon, 10 Feb 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 31 Jan 2025 08:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Emili Castells DPortfolio allows Reflected XSS. This issue affects DPortfolio: from n/a through 2.0.
Title WordPress DPortfolio plugin <= 2.0 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-11T23:24:33.360Z

Reserved: 2025-01-23T14:50:05.372Z

Link: CVE-2025-24534

cve-icon Vulnrichment

Updated: 2025-01-31T15:36:23.209Z

cve-icon NVD

Status : Deferred

Published: 2025-01-31T09:15:09.720

Modified: 2026-06-17T08:59:11.223

Link: CVE-2025-24534

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T05:15:16Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')