Portfolio Plugin

Portfolio Plugin has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2012 and 2015; all 2 are fixed as of September 2026. Their average CVSS score is 5.3, and the most serious one scores 6.3 out of 10.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 2 of the records (100%).

Every one of the 2 issues recorded for Portfolio Plugin has a vendor fix available, so running the current release closes all known holes.

All of these findings were reported by Nitin Venkatesh. Portfolio Plugin is installed on roughly 10 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 4.2.39.

Strategic Overview

Avg CVSSMedium
5.3/ 10
Patch Coverage100%
Open

0

Fixed

2

Get automatic notifications for all Portfolio Plugin vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.3CVE-2015-6523

Portfolio Plugin < 1.05 - Cross-Site Request Forgery

Read the full analysis

Vulnerability Records

2 records
Portfolio Plugin banner
Latestv1.1

Portfolio Plugin

lisa_westlund

Author

lisa_westlund

5.0(2)
100/100
Last Updated
2015-06-05 (11y ago)
Active Installs
10+
Downloads
2,765
Requires WP
0+
Requires PHP
0+
Tested up to
WP 4.2.39
Created
2015-06-02 (11y ago)

Use Instagram to display your portfolio with this responsive plugin. Choose whether to display all images from your account, or only the ones you tag with a custom hashtag. Choose whether or not to display image description/caption and publish date. Display the portfolio on a page just by using a shortcode to activate it. The authentication to your Instagram account is made on the server, which is a secure way of getting your secret access token.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C