Portfolio Plugin
Portfolio Plugin has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2012 and 2015; all 2 are fixed as of September 2026. Their average CVSS score is 5.3, and the most serious one scores 6.3 out of 10.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 2 of the records (100%).
Every one of the 2 issues recorded for Portfolio Plugin has a vendor fix available, so running the current release closes all known holes.
All of these findings were reported by Nitin Venkatesh. Portfolio Plugin is installed on roughly 10 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 4.2.39.
CVE-2015-6523Portfolio Plugin < 1.05 - Cross-Site Request Forgery
Read the full analysisVulnerability Records

Portfolio Plugin
Author
lisa_westlund
Use Instagram to display your portfolio with this responsive plugin. Choose whether to display all images from your account, or only the ones you tag with a custom hashtag. Choose whether or not to display image description/caption and publish date. Display the portfolio on a page just by using a shortcode to activate it. The authentication to your Instagram account is made on the server, which is a secure way of getting your secret access token.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C