PowerFolio <= 3.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
PowerFolio – Portfolio & Image Gallery for Elementor
Minimum safe version
3.2.2
Update to 3.2.2 or later to address 9 fixable vulnerabilities
WordPress Post Grid, Image Gallery & Portfolio for Elementor | PowerFolio Plugin <= 3.2.0 is vulnerable to Cross Site Scripting (XSS)
Freemius SDK <= 2.4.2 - Missing Authorization Checks
CVE-2024-22150
WordPress Post Grid, Image Gallery & Portfolio for Elementor | PowerFolio Plugin < 3.0.3 is vulnerable to Cross Site Scripting (XSS)
CVE-2022-4765
Freemius SDK <= 2.4.2 - Missing Authorization Checks
WordPress Post Grid, Image Gallery & Portfolio for Elementor | PowerFolio plugin <= 2.1.6 - Sensitive Information Disclosure vulnerability
WordPress Post Grid, Image Gallery & Portfolio for Elementor | PowerFolio plugin <= 2.1.6 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability