Input validation vulnerability in Portfolio by BestWebSoft – Work and Projects Presentation Plugin for WordPress 2.4.0

The Portfolio by BestWebSoft plugin for WordPress is vulnerable to a type of attack called Reflected Cross-Site Scripting. This vulnerability is present in versions of the plugin prior to 2.4.0 and occurs because input is not adequately checked and output is not properly secured. This means that unauthorised people can inject web scripts into pages which then run if a user is tricked into clicking a link.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.