CVE-2024-8276
Published
CVSS v3
6.4
MEDIUM
CVSS v2
N/A
Affected
1
PROJECT
Description
The WPZOOM Portfolio Lite – Filterable Portfolio Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’ attribute within the 'wp:wpzoom-blocks' Gutenberg block in all versions up to, and including, 1.4.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
<h4>Portfolio Gallery Plugin for WordPress</h4>
<p><strong>The easiest way to showcase your projects in WordPress.</strong> Create beautiful, filterable portfolio galleries with grid layouts, masonry design, and lightbox support. Perfect for photographers, designers, artists, freelancers, and agencies.</p>
<p><a href="https://www.wpzoom.com/plugins/portfolio-pro/" rel="nofollow ugc">WPZOOM Portfolio</a> is trusted by over 20,000 active websites. Display your work with category filtering, multiple layouts, and responsive design that looks great on all devices.</p>
<h3>Why Choose WPZOOM Portfolio?</h3>
<p>✅ <strong>Filterable Portfolio Gallery</strong> – Let visitors filter projects by category with smooth isotope animations<br />
✅ <strong>3 Layout Options</strong> – Grid with overlay, masonry, and columns layouts<br />
✅ <strong>Built-in Lightbox</strong> – Showcase high-resolution images in an elegant popup<br />
✅ <strong>Works Everywhere</strong> – Use the Portfolio block, shortcodes, or embed in any page builder<br />
✅ <strong>Blog Posts Support</strong> – Display your blog posts as a portfolio grid too<br />
✅ <strong>Mobile Responsive</strong> – Portfolio galleries look perfect on all devices</p>
<p><a href="https://demo.wpzoom.com/inspiro-lite/portfolio/" rel="nofollow ugc"><strong>View Demo</strong></a><br />
⭐️ <strong><a href="https://demo.wpzoom.com/portfolio-pro/" rel="nofollow ugc">View PRO Demo</a></strong> ⭐️</p>
<h3>💪 Want More Power? Try WPZOOM Portfolio PRO</h3>
<p>Take your portfolio to the next level with <a href="https://www.wpzoom.com/plugins/portfolio-pro/" rel="nofollow ugc"><strong>WPZOOM Portfolio PRO</strong></a>. Add video portfolios, stunning hover effects, and complete design control.</p>
<p>⭐️ <strong><a href="https://www.wpzoom.com/plugins/portfolio-pro/?utm_source=wporg&utm_medium=website&utm_campaign=free_description" rel="nofollow ugc">Get the PRO version!</a></strong> ⭐️</p>
<h3>Free Plugin Features</h3>
<p><strong>Portfolio Custom Post Type</strong></p>
<p>Create dedicated portfolio posts separate from your blog. Add titles, descriptions, featured images, and organize with categories and tags.</p>
<p><strong>Filterable Portfolio Gallery</strong></p>
<p>Let visitors filter your projects by category with smooth isotope animations. Perfect for showcasing different types of work.</p>
<p><strong>3 Layout Options</strong></p>
<p>Choose the perfect layout for your portfolio:<br />
– Grid with Overlay – Clean grid with hover effects<br />
– Masonry – Pinterest-style varied heights<br />
– Columns – Traditional multi-column layout</p>
<p><strong>Built-in Lightbox</strong></p>
<p>Display high-resolution images in an elegant popup. Visitors can browse through your portfolio without leaving the page.</p>
<p><strong>Reusable Portfolio Layouts</strong></p>
<p>Create portfolio layouts once and embed them anywhere using shortcodes. Works with Elementor, Beaver Builder, and any page builder.</p>
<p><strong>Multiple Thumbnail Sizes</strong></p>
<p>Choose from portrait, cinema, square, or uncropped aspect ratios to match your design needs.</p>
<h3>⬆️ Upgrade to WPZOOM Portfolio PRO</h3>
<p><strong>Ready for video portfolios and advanced customization?</strong> <a href="https://www.wpzoom.com/plugins/portfolio-pro/" rel="nofollow ugc">WPZOOM Portfolio PRO</a> adds powerful features for professional portfolios.</p>
<h3>🌟 PRO Features Include:</h3>
<p><strong>🎬 Video Portfolio Support</strong></p>
<p>Showcase video projects alongside images. Full support for YouTube, Vimeo, and self-hosted MP4 videos.</p>
<p><strong>▶️ Video Lightbox</strong></p>
<p>Play videos in a beautiful lightbox popup. Visitors can watch your video portfolio without leaving the page.</p>
<p><strong>🎥 Video Background on Hover</strong></p>
<p>Create stunning hover effects with video backgrounds. Add motion to your portfolio items with Giphy or self-hosted videos.</p>
<p><strong>🔀 Drag & Drop Reordering</strong></p>
<p>Arrange your portfolio items in any order with simple drag and drop. No more wrestling with dates or menu order.</p>
<p><strong>🎨 Color Customization</strong></p>
<p>Full control over colors – customize overlay colors, text colors, and hover effects to match your brand.</p>
<p><strong>Premium Support</strong></p>
<p>Get priority support from our team when you need help with your portfolio.</p>
<p><strong>Love WPZOOM Portfolio?</strong> Help other WordPress users discover this plugin by <a href="https://wordpress.org/support/plugin/wpzoom-portfolio/reviews/#new-post" rel="ugc">leaving a 5-star review</a>.</p>
<h3>Recommended Themes</h3>
<p>Works great with any theme! For the best portfolio experience, check out:<br />
<a href="https://www.wpzoom.com/themes/inspiro/" rel="nofollow ugc"><strong>Inspiro Premium</strong></a><br />
<a href="https://wordpress.org/themes/inspiro/" rel="ugc"><strong>Inspiro Lite</strong></a><br />
<a href="https://wordpress.org/themes/inspiro-blocks/" rel="ugc"><strong>Inspiro Blocks</strong></a> 🆕<br />
<a href="https://www.wpzoom.com/themes/inspiro-blocks-pro/" rel="nofollow ugc"><strong>Inspiro Blocks PRO</strong></a> 🆕</p>
<h3>Additional Resources</h3>
<ul>
<li><a href="https://www.wpzoom.com/documentation/wpzoom-portfolio-grid/" rel="nofollow ugc">Plugin Documentation</a> – Step-by-step guides</li>
<li><a href="https://www.wpzoom.com/" rel="nofollow ugc">WPZOOM Official Site</a> – See our complete product lineup</li>
<li><a href="https://github.com/wpzoom/WPZOOM-Portfolio" rel="nofollow ugc">GitHub Repository</a> – Contribute to development</li>
</ul>
<h3>100% GDPR Compliant</h3>
<p>This plugin doesn’t integrate any Google Fonts or collect any information outside your WordPress installation.</p>