Known CVE
WPZOOM Portfolio <= 1.4.21 - Reflected Cross-Site Scripting
WPZOOM Portfolio <= 1.4.21 contains a reflected XSS caused by improper neutralization of input during web page generation, letting attackers execute scripts in victim's browser, exploit requires crafted request.
CVE-2026-49069
High2026CVSS 7.1CWE-79
cve2026 · wordpress · wp · wp-plugin · wpzoom · xss · unauth
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website