Themify Portfolio Post
Themify Portfolio Post has 6 disclosed vulnerabilities in the WordSec catalog, reported between 2020 and 2025; all 6 are fixed as of September 2026. Their average CVSS score is 5.9, and the most serious one scores 6.4 out of 10. 2023 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Scripting, behind 6 of the records (100%).
Every one of the 6 issues recorded for Themify Portfolio Post has a vendor fix available, so running the current release closes all known holes.
5 independent researchers contributed these findings, most of them (2) reported by István Márton. Themify Portfolio Post is installed on roughly 30,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2025-67533Themify Portfolio Post <= 1.3.0 - Authenticated (Author+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records
Themify Portfolio Post
Author
themifyme
Themify Portfolio Posts is a simple plugin that allows you to showcase your projects info in a clean layout. Minimal and sleek, you can click on each image of your gallery portfolio and opt to show further details such as the project type, client name, and commission date – or edit each heading and name your own. Themify Portfolio Post plugin is compatible with any theme and users can install it on their WordPress admin dashboard like all other plugins.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C