CVE-2026-42415: WordPress Porto Theme - Functionality plugin <= 3.9.3 - SQL Injection vulnerability
Published Oct 6, 2026
·Updated
Unauthenticated SQL Injection in Porto Theme - Functionality <= 3.9.3 versions.
Affected Software
1 affected component
Porto Theme Functionality plugin<=3.9.3
Event History
Oct 6, 2026
CVE Published
via MITRE·08:34 AM
Data Sourced
via MITRE·08:34 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or prior access to the site. Network access to the affected site is sufficient.
2
Which installations are affected?
Porto Theme Functionality plugin versions 3.9.3 and earlier are affected. The available information does not identify a configuration prerequisite or workaround.
3
What is the likely impact?
This is a critical SQL injection issue with high confidentiality impact and low availability impact. Its vector is network-accessible, requires low attack complexity, and requires no user interaction.