CRITICAL 9.3 CVE-2026-42415 Published 6 Oct 2026

Porto Theme Functionality Plugin SQL Injection Vulnerability

Worried this affects your website?

Porto Theme – Functionality versions up to and including 3.9.3 are affected by an unauthenticated SQL injection vulnerability.

This flaw allows attackers to perform SQL injection without requiring authentication.

  • Affected versions: <= 3.9.3
  • Condition: unauthenticated access

Reference: CVE-2026-42415 on NVD

← Back to Security News