Themify Portfolio Post

Themify Portfolio Post has 6 disclosed vulnerabilities in the WordSec catalog, reported between 2020 and 2025; all 6 are fixed as of September 2026. Their average CVSS score is 5.9, and the most serious one scores 6.4 out of 10. 2023 was the busiest year with 2 disclosures.

The most common weakness is Cross-Site Scripting, behind 6 of the records (100%).

Every one of the 6 issues recorded for Themify Portfolio Post has a vendor fix available, so running the current release closes all known holes.

5 independent researchers contributed these findings, most of them (2) reported by István Márton. Themify Portfolio Post is installed on roughly 30,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

Strategic Overview

Avg CVSSMedium
5.9/ 10
Patch Coverage100%
Open

0

Fixed

6

Get automatic notifications for all Themify Portfolio Post vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.4CVE-2025-67533

Themify Portfolio Post <= 1.3.0 - Authenticated (Author+) Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

6 records
Plugin Profile
Latestv1.3.3

Themify Portfolio Post

themifyme

Author

themifyme

5.0(1)
100/100
Last Updated
2026-08-05 (1mo ago)
Active Installs
30,000+
Downloads
719,488
Requires WP
5.2+
Requires PHP
7.2+
Tested up to
WP 7.0.4
Created
2018-05-11 (9y ago)

Themify Portfolio Posts is a simple plugin that allows you to showcase your projects info in a clean layout. Minimal and sleek, you can click on each image of your gallery portfolio and opt to show further details such as the project type, client name, and commission date – or edit each heading and name your own. Themify Portfolio Post plugin is compatible with any theme and users can install it on their WordPress admin dashboard like all other plugins.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C