VendorsPWR Pluginspowerfolioall versions
Vulnerabilities

PWR Plugins PowerFolio

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2024-22150
WordPress Post Grid, Image Gallery & Portfolio for Elementor | PowerFolio Plugin <= 3.1 is vulnerable to Cross Site Scripting (XSS)
Published 2024-01-31 · Modified
6.5EPSS 0.003
CVE-2025-7046
Portfolio for Elementor & Image Gallery | PowerFolio <= 3.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom JS
Published 2025-07-04 · Analyzed
6.4EPSS 0.002