Impact
The vulnerability is a stored cross‑site scripting (XSS) flaw that allows an authenticated Contributor‑level user to inject arbitrary JavaScript through the Custom JS attributes of the PowerFolio widgets. The injection is not properly sanitized or escaped, so the malicious script is saved in the database and executed whenever any user views the affected page, enabling attackers to steal session cookies, deface content, or redirect users to phishing sites. This weakness is classified as CWE‑79.
Affected Systems
The flaw exists in all releases of the PowerFolio – Portfolio & Image Gallery for Elementor plugin up to and including version 3.2.0. The plugin is provided by dotrex and functions as a WordPress plugin. A partial fix was applied in version 3.2.0, but a full resolution was not reached until version 3.2.1.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate severity impact. With an EPSS score of less than 1% the probability of exploitation is low, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to hold at least Contributor access, which is typically authenticated. Once an attacker achieves that privilege, they can inject scripts that execute in the browsers of all users who load the targeted page, potentially granting them stealthy persistent access.
OpenCVE Enrichment
EUVD