Opal Portfolio
Opal Portfolio has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Opal Portfolio has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
All of these findings were reported by 0xd4rk5id3. Opal Portfolio is installed on roughly 100 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 5.0.27.
CVE-2025-31748Opal Portfolio <= 1.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

Opal Portfolio
Author
wpopal
Opal Portfolio is a flexible WordPress plugin that lets you display your company’s portfolios in a variety of ways: as single pages, and even as embedded content blocks on the homepage of your website with the help of custom shortcodes. Features Guide shortcodes : Opal Portfolio >> Setting >> Shortcodes Benefits For Users With Powerful Functions Of Potential Websites Completely integrated with Elementor page builder! 100% responsive and mobile ready Easily Integrated to any WordPress websites. Quickly Set up, Publish & Update Friendly-user and Easy Customization Configuration The plugin is highly customizable, so you can apply it to any WordPress theme. In the settings section of the plugin you can do the following: Setting >> Display Setting – Can change the ‘Slug’ of Portfolio and Portfolio category; – Select page view layour for Portfolio pages; – Select image sizes for Portfolio pages; – Set a columns for to Portfolio pages; – Set the number of services displayed on Portfolio pages; – Choose display Thumnail, Category, Description, View Detail, Number for to Portfolio pages;
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C