Skip to content

Known CVE

WPZOOM Portfolio <= 1.4.21 - Reflected Cross-Site Scripting

WPZOOM Portfolio <= 1.4.21 contains a reflected XSS caused by improper neutralization of input during web page generation, letting attackers execute scripts in victim's browser, exploit requires crafted request.

CVE-2026-49069

High2026CVSS 7.1CWE-79

cve2026 · wordpress · wp · wp-plugin · wpzoom · xss · unauth

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website