Skip to content
Noroxi

pwrplugins records

5 published records for vendor pwrplugins.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
40%
Median publish → KEV
No record has entered KEV

Records by year

  1. 23
  2. 24
  3. 25

Bar: total · dark part: CISA KEV.

Recurring classes

The weakness classes this vendor ships most often: where to look.

CWE

Attack profile

All records

5 records
  • CVE-2022-4765
    21Monitor

    Portfolio for Elementor, Image Gallery & Post Grid | PowerFolio < 2.3.1 - Contributor+ Stored XSS via Shortcode

    MediumCVSS 5.4No exploitEPSS 1%

    pwrplugins · portfolio for elementorJan 30, 2023

  • WordPress Post Grid, Image Gallery & Portfolio for Elementor | PowerFolio Plugin <= 3.1 is vulnerable to Cross Site Scripting (XSS)

    MediumCVSS 5.4No exploitEPSS 0%

    pwrplugins · powerfolioJan 31, 2024

  • CVE-2025-7046
    21Monitor

    Portfolio for Elementor & Image Gallery | PowerFolio <= 3.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom JS

    MediumCVSS 5.4No exploitEPSS 0%

    pwrplugins · powerfolioJul 3, 2025

  • CVE-2025-6687
    21Monitor

    Magic Buttons for Elementor <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via magic-button Shortcode

    MediumCVSS 5.4No exploitEPSS 0%

    pwrplugins · magic buttons for elementorJul 2, 2025

  • CVE-2025-6686
    21Monitor

    Magic Buttons for Elementor <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via magic-button Shortcode

    MediumCVSS 5.4No exploitEPSS 0%

    pwrplugins · magic buttons for elementorJul 2, 2025