Visualportfolio develops a focused WordPress plugin for creating visual portfolio and gallery displays, with its vulnerability surface centered on authorization and access-control issues across its photo gallery and post grid functionality. The recurrent weakness pattern of incorrect and missing authorization reflects common challenges in plugin-based permission management within the WordPress ecosystem. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Visualportfolio over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-2543MEDIUM The Visual Portfolio, Photo Gallery & Post Grid WordPress plugin before 2.18.0 does not have proper authorisation checks in some of its REST endpoints, allowing unauthenticated use | Sep 5, 2022 | 6.1 | 22 | NO | NO |
CVE-2022-2597MEDIUM The Visual Portfolio, Photo Gallery & Post Grid WordPress plugin before 2.19.0 does not have proper authorisation checks in some of its REST endpoints, allowing users with a role a | Sep 5, 2022 | 5.4 | 15 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Visualportfolio.
Media articles that mention a CVE ID that affects a product developed by Visualportfolio — matched by CVE ID, not by vendor name.