CVE · Medium

CVE-2023-48739 — Porto Functionality [porto-functionality] < 2.12.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-48739 Porto Functionality [porto-functionality] < 2.12.1 Missing Authorization Medium 5.3 < 2.12.1 2.12.1 2023-11-23

CVE-2023-48739

The Porto Functionality plugin in versions before 2.12.1 contains a broken access control vulnerability that was discovered by Rafie Muhammad and reported through Patchstack. The flaw stems from inadequate authorization checks in a plugin function, which allows unauthenticated or low-privileged users to perform actions that should be restricted to higher-privileged administrators. As of the advisory date, no patched version addressing this issue had been released.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.