CVE-2015-6523: Portfolio Project Portfolio

Medium severity, CVSS 6.8. EPSS: 1.2% chance of exploitation in the next 30 days.

Cross-site request forgery (CSRF) vulnerability in the Portfolio plugin before 1.05 for WordPress allows remote attackers to hijack the authentication of administrators for requests that have unspecified impact via a request to the instagram-portfolio page in wp-admin/options-general.php.

Affected products

Published 2015-08-19. Last modified 2026-06-17.