Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bestweblayout Portfolio portfolio allows DOM-Based XSS.This issue affects Portfolio : from n/a through <= 2.58.
Published: 2025-09-22
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper neutralization of user input during web page generation, allowing a DOM‑based cross‑site scripting (XSS) attack. An attacker can inject malicious JavaScript through crafted input, potentially hijacking user sessions, compromising site integrity, or delivering malware. The flaw is identified as CWE‑79, indicating a weakness in input validation and output encoding. The reported CVSS score of 5.9 reflects a moderate severity, indicating that while exploitation is feasible, it does not automatically provide remote code execution or system compromise.

Affected Systems

The issue affects the "bestweblayout Portfolio" WordPress plugin versions from the earliest available release through 2.58. Any installation of the Portfolio plugin at or below version 2.58 is vulnerable.

Risk and Exploitability

With a CVSS of 5.9 and an EPSS of less than 1 %, the likelihood of public exploitation is low, and the vulnerability is not listed in the CISA KEV catalog. The vulnerability is a DOM‑based XSS, so the likely attack vector involves an attacker supplying malicious payloads via plugin input fields, URL parameters, or other user‑controlled data that is echoed without proper escaping. Successful exploitation would allow the attacker to execute arbitrary scripts in the context of site visitors. The low EPSS indicates that, so far, no widespread exploitation is known.

Generated by OpenCVE AI on April 30, 2026 at 01:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Portfolio plugin to a version beyond 2.58, ensuring the fix is applied
  • If an upgrade is not immediately possible, disable or delete the vulnerable plugin to stop the attack surface
  • Apply rigorous input sanitization and output escaping for any data that the plugin processes, following best practices for CW‑79 mitigations

Generated by OpenCVE AI on April 30, 2026 at 01:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-30584 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bestweblayout Portfolio allows DOM-Based XSS. This issue affects Portfolio : from n/a through 2.58.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bestweblayout Portfolio allows DOM-Based XSS. This issue affects Portfolio : from n/a through 2.58. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bestweblayout Portfolio portfolio allows DOM-Based XSS.This issue affects Portfolio : from n/a through <= 2.58.
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Tue, 23 Sep 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 23 Sep 2025 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Bestweblayout
Bestweblayout portfolio
Wordpress
Wordpress wordpress
Vendors & Products Bestweblayout
Bestweblayout portfolio
Wordpress
Wordpress wordpress

Mon, 22 Sep 2025 18:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bestweblayout Portfolio allows DOM-Based XSS. This issue affects Portfolio : from n/a through 2.58.
Title WordPress Portfolio Plugin <= 2.58 - Cross Site Scripting (XSS) Vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Bestweblayout Portfolio
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:42.762Z

Reserved: 2025-08-27T16:19:44.959Z

Link: CVE-2025-58245

cve-icon Vulnrichment

Updated: 2025-09-23T15:57:54.850Z

cve-icon NVD

Status : Deferred

Published: 2025-09-22T19:16:10.167

Modified: 2026-04-23T15:33:22.517

Link: CVE-2025-58245

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T01:30:24Z

Weaknesses