Wpsofts develops WordPress gallery and portfolio plugins, with observed vulnerabilities concentrating in cross-site scripting issues within its grid-kit portfolio products. Treat this as a narrow vendor profile centered on web-application input-handling concerns; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpsofts over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-25090MEDIUM The Portfolio Gallery, Product Catalog WordPress plugin before 2.1.0 does not have authorisation and CSRF checks in various functions related to AJAX actions, allowing any authenti | Apr 11, 2022 | 5.4 | 20 | NO | NO |
CVE-2023-3292MEDIUM The grid-kit-premium WordPress plugin before 2.2.0 does not escape some parameters as well as generated URLs before outputting them in attributes, leading to Reflected Cross-Site S | Jul 31, 2023 | 6.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpsofts.
Media articles that mention a CVE ID that affects a product developed by Wpsofts — matched by CVE ID, not by vendor name.