Impact
The Behance Portfolio Manager plugin for WordPress contains a stored cross‑site scripting flaw caused by insufficient input sanitization. Malicious script code can be stored in fields such as portfolio description or title and later served to visitors of the affected website. This type of flaw can compromise the confidentiality and integrity of the site, allow attackers to hijack user sessions, and potentially spread malware, resulting in defacement or unauthorized data disclosure.
Affected Systems
The vulnerability applies to the eleopard Behance Portfolio Manager plugin version 1.7.5 and earlier. Any WordPress installation that has this plugin installed is potentially exposed. No specific WordPress core version constraints were listed, so the risk applies irrespective of the underlying WordPress version.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. The EPSS score is reported as < 1 %, suggesting that the likelihood of automated exploitation is low. The vulnerability is not listed in the CISA KEV catalog. The attack vector is web‑based; it requires an attacker to have the ability to submit content to the plugin’s input fields, but no local privileges are necessary. Once stored, the malicious script executes in the browsers of site visitors, providing typical XSS damage such as cookie theft or user impersonation.
OpenCVE Enrichment
EUVD