VYPR

GS Portfolio for Envato

by WordPress

CVEs (2)

  • CVE-2023-0559MedFeb 21, 2023
    risk 0.35cvss 5.4epss 0.00

    The GS Portfolio for Envato WordPress plugin before 1.4.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embedded, which could allow users with the contributor role and above to perform Stored…

  • CVE-2025-62755MedDec 31, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in GS Plugins GS Portfolio for Envato gs-envato-portfolio allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GS Portfolio for Envato: from n/a through <= 1.4.2.