DOM-Based XSS Vulnerability in BestWebLayout's Portfolio Plugin
CVE-2025-58245
5.9MEDIUM
What is CVE-2025-58245?
A vulnerability in BestWebLayout's Portfolio plugin allows for DOM-based Cross-site Scripting (XSS) due to improper input neutralization during web page generation. This flaw can be exploited by attackers to inject malicious scripts, potentially compromising user data and session information. Users of Portfolio plugin versions up to 2.58 should implement immediate security measures to safeguard against this vulnerability.
Affected Version(s)
Portfolio <= 2.58