Extension WordPress
Vulnérabilités Porto Theme – Functionality
Cette page rassemble les failles publiées pour Porto Theme – Functionality, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Porto Theme – Functionality
6 fiches
Porto Theme – Functionality < 3.7.3 – Missing Authorization
The Porto Theme – Functionality plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and excluding, 3.7.3. This makes it possible for authenticated attackers, with subscriber-level…
[*, 3.7.3)
3.7.3
12/10/2025
Porto Theme – Functionality < 3.7.3 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Porto Theme – Functionality plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and excluding, 3.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…
[*, 3.7.3)
3.7.3
11/10/2025
Porto Theme – Functionality <= 3.1.0 – Authenticated (Contributor+) Local File Inclusion via Shortcode
The Porto Theme – Functionality plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.1.0 via the 'porto_portfolios' shortcode 'portfolio_layout' attribute. This makes it possible for authenticated attackers, with contributor-level and…
*-3.1.0
3.1.1
08/05/2024
Porto Theme – Functionality <= 3.0.9 – Authenticated (Contributor+) Local File Inclusion via Post Meta
The Porto Theme – Functionality plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.0.9 via the 'slideshow_type' post meta. This makes it possible for authenticated attackers, with contributor-level and above…
*-3.0.9
3.1.0
08/05/2024
Porto Theme – Functionality <= 2.11.1 – Unauthenticated SQL Injection
The Porto Theme – Functionality plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.11.1 due to insufficient escaping on a user supplied parameter and lack of sufficient preparation on an existing SQL…
*-2.11.1
2.12.1
23/11/2023
Porto Theme – Functionality <= 2.11.1 – Missing Authorization
The Porto Theme – Functionality plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on an unknown function in versions up to, and including, 2.11.1. This makes it possible for unauthenticated…
*-2.11.1
2.12.1
23/11/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.