Junglewise Threat Intelligence

CVE-2025-59135: eleopard Behance Portfolio Manager stored cross-site scripting

CVE-2025-59135 · Severity: medium · CVSS 5.9 · Published 2025-12-31

Executive brief

The Behance Portfolio Manager is a WordPress plugin that displays portfolio galleries on websites. This vulnerability allows authenticated administrators to inject malicious scripts into the plugin's settings, which are then executed in the browsers of site visitors and other administrators, potentially stealing credentials or hijacking accounts.

Technical details

This is a stored cross-site scripting (XSS) vulnerability in the eleopard Behance Portfolio Manager WordPress plugin (versions ≤ 1.7.5). The vulnerability exists due to improper sanitization of user input during web page generation. An authenticated administrator or developer with plugin settings access can inject malicious JavaScript that persists in the database. When other users (including administrators) access affected pages or plugin settings, the stored payload executes in their browser context. Exploitation requires administrator or developer-level access and user interaction (visiting a crafted page). The vulnerability is fixed in version 1.8.0.

Affected products

  • eleopard Behance Portfolio Manager through 1.7.5

Timeline

  • 2025-10-03: disclosed: Reported to Patchstack by Nguyen Tran Tuan Dung
  • 2025-12-31: advisory: Published by Patchstack
  • 2025-12-31: patched: Version 1.8.0 contains fix

References