PLUGIN SECURITY

Is Porto Functionality safe?

WooCommerce Product Badge and Label, Sale Badge, Sold Out Badge, Countdown Timer, Notification Bar (PRO), Quick View, out-of-stock badge.

What this plugin does

  • Slug: porto-functionality
  • Author: AsanaPlugins
  • 5000+ active installs
  • 96/100 rating (30 reviews on wordpress.org)
  • 141910 all-time downloads
  • On WordPress.org since 2023-12-18

badgeproduct labelsale badgewoocommerceWoocommerce badge

Maintenance status

  • Latest known version: 7.3.2
  • Last updated: 2026-09-01 9:38am GMT
  • Tested up to WordPress: 7.1
  • Requires PHP: 5.6+

Known vulnerabilities

6 known CVEs on file for Porto Functionality. Reported between 2023 and 2025.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-63067 Porto Functionality [porto-functionality] < 3.7.3 Missing Authorization Medium 4.3 < 3.7.3 3.7.3 2025-10-12 ✓ fixed in latest
CVE-2025-63066 Porto Functionality [porto-functionality] < 3.7.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 3.7.3 3.7.3 2025-10-11 ✓ fixed in latest
CVE-2024-3809 Porto Functionality [porto-functionality] < 3.1.0 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') High 8.8 < 3.1.0 3.1.0 2024-05-08 ✓ fixed in latest
CVE-2024-3808 Porto Functionality [porto-functionality] < 3.1.1 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') High 8.8 < 3.1.1 3.1.1 2024-05-08 ✓ fixed in latest
CVE-2023-48739 Porto Functionality [porto-functionality] < 2.12.1 Missing Authorization Medium 5.3 < 2.12.1 2.12.1 2023-11-23 ✓ fixed in latest
CVE-2023-48738 Porto Functionality [porto-functionality] < 2.12.1 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Critical 9.3 < 2.12.1 2.12.1 2023-11-23 ✓ fixed in latest

How to fix it

Keep Porto Functionality updated — 7.3.2 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.