CRITICAL
9.3 CVE-2026-42415 Published 6 Oct 2026
Porto Theme Functionality Plugin SQL Injection Vulnerability
Worried this affects your website?
Porto Theme – Functionality versions up to and including 3.9.3 are affected by an unauthenticated SQL injection vulnerability.
This flaw allows attackers to perform SQL injection without requiring authentication.
- Affected versions: <= 3.9.3
- Condition: unauthenticated access
Reference: CVE-2026-42415 on NVD
← Back to Security News