Impact
The PowerFolio plugin contains a stored cross‑site scripting flaw that allows an attacker to embed malicious scripts into content returned by the site. The flaw lies in improper neutralization of input during web page generation, classified as CWE‑79. An attacker who can create or edit portfolio items could store JavaScript that will execute in the browsers of any visitor to the affected page, compromising confidentiality and integrity of user sessions.
Affected Systems
The vulnerability affects all installations of the Diego Pereira PowerFolio WordPress plugin up to and including version 3.2.1. WordPress sites hosting this plugin before any update are susceptible.
Risk and Exploitability
The CVSS score is 6.5, indicating a moderate impact if successfully exploited. EPSS is below 1 %, suggesting low probability of exploitation in the wild, and the vulnerability has not been listed in the CISA KEV catalog. Exploitation likely requires the attacker to have permission to add or modify portfolio content; once injected, stored scripts run automatically in visitors’ browsers.
OpenCVE Enrichment
EUVD