Impact
The WPZOOM Portfolio plugin contains a reflected cross‑site scripting flaw caused by improper neutralization of user input during web page generation. An attacker can insert malicious scripts that are executed in the browser of any visitor who views an affected page, potentially allowing defacement, cookie theft, session hijacking or other client‑side attacks. The severity is medium‑high, as reflected XSS can compromise the confidentiality and integrity of data for victim users and, depending on the page context, malicious actions.
Affected Systems
This vulnerability affects the WPZOOM Portfolio WordPress plugin for all releases through version 1.4.29. The plugin is distributed by the vendor WPZOOM and integrated into WordPress sites that install it.
Risk and Exploitability
The reported CVSS score of 7.1 indicates a significant risk; the EPSS score of <1% indicates a low likelihood of exploitation in the wild so far, and the issue is not listed in the CISA KEV catalog. The XSS means an attacker needs or submits a malicious value that the plugin echoes unsanitized. If triggered, the attacker can execute arbitrary JavaScript in the victim’s browser session.
OpenCVE Enrichment