CVE-2023-48739
The Porto Functionality plugin in versions before 2.12.1 contains a broken access control vulnerability that was discovered by Rafie Muhammad and reported through Patchstack. The flaw stems from inadequate authorization checks in a plugin function, which allows unauthenticated or low-privileged users to perform actions that should be restricted to higher-privileged administrators. As of the advisory date, no patched version addressing this issue had been released.
Based on public CVE data (MITRE/NVD).