Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPZOOM WPZOOM Portfolio wpzoom-portfolio allows Reflected XSS.This issue affects WPZOOM Portfolio: from n/a through <= 1.4.29.
Published: 2026-07-13
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The WPZOOM Portfolio plugin contains a reflected cross‑site scripting flaw caused by improper neutralization of user input during web page generation. An attacker can insert malicious scripts that are executed in the browser of any visitor who views an affected page, potentially allowing defacement, cookie theft, session hijacking or other client‑side attacks. The severity is medium‑high, as reflected XSS can compromise the confidentiality and integrity of data for victim users and, depending on the page context, malicious actions.

Affected Systems

This vulnerability affects the WPZOOM Portfolio WordPress plugin for all releases through version 1.4.29. The plugin is distributed by the vendor WPZOOM and integrated into WordPress sites that install it.

Risk and Exploitability

The reported CVSS score of 7.1 indicates a significant risk; the EPSS score of <1% indicates a low likelihood of exploitation in the wild so far, and the issue is not listed in the CISA KEV catalog. The XSS means an attacker needs or submits a malicious value that the plugin echoes unsanitized. If triggered, the attacker can execute arbitrary JavaScript in the victim’s browser session.

Generated by OpenCVE AI on August 1, 2026 at 10:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Await and apply an official vendor patch or newer release that fixes the XSS flaw (no specific version known).
  • Deploy a web application firewall rule that blocks or sanitizes the input parameters used by the plugin.
  • Disable or uninstall the plugin to eliminate the vulnerable code.

Generated by OpenCVE AI on August 1, 2026 at 10:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wpzoom
Wpzoom wpzoom Portfolio
Vendors & Products Wordpress
Wordpress wordpress
Wpzoom
Wpzoom wpzoom Portfolio

Mon, 13 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPZOOM WPZOOM Portfolio wpzoom-portfolio allows Reflected XSS.This issue affects WPZOOM Portfolio: from n/a through <= 1.4.29.
Title WordPress WPZOOM Portfolio plugin <= 1.4.29 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
Wpzoom Wpzoom Portfolio
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T13:39:32.425Z

Reserved: 2026-06-25T08:04:04.790Z

Link: CVE-2026-57712

cve-icon Vulnrichment

Updated: 2026-07-13T13:39:26.502Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T10:45:03Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')