Junglewise Threat Intelligence

CVE-2026-57712: WPZOOM Portfolio reflected XSS in WordPress plugin

CVE-2026-57712 · Severity: high · CVSS 7.1 · Published 2026-07-13

Vendors: WPZOOM.

Executive brief

WPZOOM Portfolio is a WordPress plugin used to create and display professional portfolios on websites. A security vulnerability in this plugin allows attackers to inject malicious scripts into the site, which are then executed in the browsers of other users. This could lead to unauthorized actions being performed on behalf of site administrators, theft of session information, or the display of fraudulent content to visitors.

Technical details

The WPZOOM Portfolio plugin for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) in versions up to 1.4.29. The vulnerability stems from the improper neutralization of user-supplied input during web page generation (CWE-79). An unauthenticated remote attacker can exploit this by tricking a user (typically an administrator) into clicking a specially crafted link. Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's browser session, potentially leading to session hijacking or unauthorized administrative actions. The issue is resolved in version 1.4.30.

Affected products

  • WPZOOM WPZOOM Portfolio <= 1.4.29

Timeline

  • 2026-06-23: other: Reported by researcher Thaer Assfour
  • 2026-07-10: advisory: Patchstack advisory published
  • 2026-07-13: disclosed: CVE published to NVD

References

Related threats