PT-2025-49909 · WordPress · Themify Portfolio Post

Published

2025-12-09

·

Updated

2025-12-15

·

CVE-2025-67533

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Themify Portfolio Post versions through 1.3.0
Description A flaw exists in Themify Portfolio Post that allows for cross-site scripting (XSS). This issue involves improper neutralization of input during web page generation. The vulnerability allows for stored XSS attacks, meaning malicious scripts can be stored on the target server and executed by other users.
Recommendations Update Themify Portfolio Post to a version newer than 1.3.0.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-67533

Affected Products

Themify Portfolio Post