Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in eleopard Behance Portfolio Manager portfolio-manager-powered-by-behance allows Blind SQL Injection.This issue affects Behance Portfolio Manager: from n/a through <= 1.7.5.
Published: 2025-04-04
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This flaw is an improper neutralization of special elements in an SQL command (CWE‑89), resulting in a blind SQL injection vulnerability in the Eleopard Behance Portfolio Manager WordPress plugin. The attacker can craft malicious input that is embedded in a database query without proper escaping, permitting unauthorized read or alteration of the underlying database. Because the vulnerability is blind, the attacker can infer data existence or table structure by observing timing or error responses, which can then lead to credential compromise, data exfiltration, or full database takeover.

Affected Systems

The vulnerable component is the Behance Portfolio Manager plugin from Eleopard for WordPress, affecting all releases up through version 1.7.5. Users running WordPress installations with this plugin version have an exposed entry point that can be exploited remotely.

Risk and Exploitability

The CVSS score of 7.6 indicates a fairly high severity, but the EPSS score of less than 1% suggests a very low probability that attackers are actively targeting this flaw. The vulnerability is not listed in the CISA KEV catalog. Because the flaw allows blind SQL injection, an attacker who can send crafted HTTP requests to the plugin endpoints could potentially read sensitive data or modify database tables, depending on permissions of the underlying database user. The attack vector is likely remote, requiring access to the web application, and no local privileges are necessary. Remediation is available by upgrading the plugin.

Generated by OpenCVE AI on May 1, 2026 at 11:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Behance Portfolio Manager plugin to the latest version that addresses the SQL injection flaw.
  • If an immediate update is not possible, disable the plugin or remove its functionality until a patch is applied.
  • Implement firewall rules to block suspicious query patterns or restrict access to the plugin’s administrative interface to authorized users only.
  • Monitor application logs for anomalous query activity and consider implementing input validation for any remaining exposed parameters.

Generated by OpenCVE AI on May 1, 2026 at 11:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-9884 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in eleopard Behance Portfolio Manager allows Blind SQL Injection. This issue affects Behance Portfolio Manager: from n/a through 1.7.4.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in eleopard Behance Portfolio Manager allows Blind SQL Injection. This issue affects Behance Portfolio Manager: from n/a through 1.7.4. Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in eleopard Behance Portfolio Manager portfolio-manager-powered-by-behance allows Blind SQL Injection.This issue affects Behance Portfolio Manager: from n/a through <= 1.7.5.
Title WordPress Behance Portfolio Manager plugin <=1.7.4 - SQL Injection vulnerability WordPress Behance Portfolio Manager plugin <= 1.7.5 - SQL Injection vulnerability
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L'}


Fri, 04 Apr 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 04 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in eleopard Behance Portfolio Manager allows Blind SQL Injection. This issue affects Behance Portfolio Manager: from n/a through 1.7.4.
Title WordPress Behance Portfolio Manager plugin <=1.7.4 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:16.746Z

Reserved: 2025-04-04T10:00:34.177Z

Link: CVE-2025-32124

cve-icon Vulnrichment

Updated: 2025-04-04T19:55:19.542Z

cve-icon NVD

Status : Deferred

Published: 2025-04-04T16:15:20.027

Modified: 2026-04-23T15:28:36.180

Link: CVE-2025-32124

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T11:30:15Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')