Medium severity5.4NVD Advisory· Published Apr 11, 2022· Updated Jun 17, 2026
CVE-2021-25090
CVE-2021-25090
Description
The Portfolio Gallery, Product Catalog WordPress plugin before 2.1.0 does not have authorisation and CSRF checks in various functions related to AJAX actions, allowing any authenticated users, such as subscriber, to call them. Due to the lack of sanitisation and escaping, it could also allows attackers to perform Cross-Site Scripting attacks on pages where a Portfolio is embed
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- WordPress/Portfolio Gallery, Product Catalog plugindescription
- cpe:2.3:a:wpsofts:portfolio_gallery\,_product_catalog_-_grid_kit_portfolio:*:*:*:*:*:wordpress:*:*Range: <2.1.0
- Range: <2.1.0
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/32a4a2b5-ef65-4e29-af4a-f003dbd0809cnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.