Input validation vulnerability in Penci Portfolio 3.5

The Penci Portfolio plugin for WordPress has a security issue called Stored Cross-Site Scripting. This can happen in versions up to 3.5 because there is not enough protection for the information put into the plugin and the information shown to users. This means that someone who is logged in and has contributor-level access or higher can add harmful web scripts to pages. These scripts will run whenever someone views the page with the harmful script on it.

Detected in:

Penci Portfolio fixed vulnerable versions: >= * <= 3.5

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.