CVE-2024-4473
The Sydney Toolbox plugin contains a stored cross-site scripting vulnerability in the aThemes Portfolio widget affecting versions 1.31 and below, caused by inadequate sanitization of user input and escaping of output in widget attributes. Attackers with contributor-level permissions or higher can inject malicious scripts into pages that will execute when other users view the affected content. This vulnerability impacts all versions up to and including 1.31, with fixes expected in version 1.32 and later.
Based on public CVE data (MITRE/NVD).