Executive brief
WPZOOM Portfolio is a WordPress plugin used to showcase creative work and projects on websites. A security flaw in this plugin allows attackers to trick a site visitor or administrator into clicking a malicious link, which then executes unauthorized code in their browser. This could lead to unauthorized actions being taken on the site, theft of session information, or the display of fraudulent content to users.
Technical details
A Reflected Cross-Site Scripting (XSS) vulnerability exists in the WPZOOM Portfolio plugin for WordPress (versions <= 1.4.21) due to insufficient sanitization and output encoding of user-supplied input during web page generation. An unauthenticated remote attacker can exploit this by crafting a malicious URL containing JavaScript and tricking a user into interacting with it. Upon execution, the script runs within the context of the victim's browser session, potentially allowing for session hijacking, unauthorized administrative actions, or website defacement. The issue is resolved in version 1.4.22.
Affected products
- WPZOOM WPZOOM Portfolio <= 1.4.21
Timeline
- 2026-05-26: other: Reported by Kent Apostol
- 2026-06-08: advisory: Patchstack advisory published
- 2026-06-10: disclosed: NVD publication date
- 2026-06-08: patched: Version 1.4.22 released to address the vulnerability