CVE · Medium

CVE-2025-63067 — Porto Functionality [porto-functionality] < 3.7.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-63067 Porto Functionality [porto-functionality] < 3.7.3 Missing Authorization Medium 4.3 < 3.7.3 3.7.3 2025-10-12

CVE-2025-63067

A security flaw exists in the Porto Theme - Functionality plugin for WordPress, allowing users with elevated privileges to bypass intended access controls due to inadequate permission checks on a specific function. Versions of the plugin prior to 3.7.3 are affected by this issue. Authorized attackers can exploit it to execute unauthorized actions within the system.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.