CVE-2025-1757
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Published Feb 28, 2025
Updated: Mar 10, 2025
CWE ID 79
Summary
CVE-2025-1757 is a Stored Cross-Site Scripting (XSS) vulnerability affecting the WordPress Portfolio Builder – Portfolio Gallery plugin. This issue, present in all versions up to 1.1.7, allows authenticated attackers with contributor-level access or higher to inject malicious scripts into the 'pfhub_portfolio' and 'pfhub_portfolio_portfolio' shortcodes via insufficient input sanitization and output escaping. Successful exploitation results in injected scripts executing whenever a user accesses an affected page.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- WordPress