Impact
The Porto Theme – Functionality plugin for WordPress contains a missing authorization flaw that allows attackers to bypass intended access controls. The vulnerability enables exploitation of improperly configured security levels, potentially granting unauthorized users the ability to carry out actions reserved for privileged users, such as modifying plugin settings or accessing sensitive data. Because the flaw stems from an access control weakness (CWE‑862), it can be leveraged to compromise the integrity or confidentiality of the WordPress site if exploited successfully.
Affected Systems
The issue impacts the Porto Theme – Functionality plugin from all releases prior to 3.7.3. Any WordPress installation running a version of this plugin before that update is vulnerable.
Risk and Exploitability
The CVSS base score of 4.3 places the issue in the medium range, although the EPSS score of less than 1% suggests the probability of exploitation is currently very low. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to craft specific web requests against the plugin’s endpoints or exploit misconfigured access control settings, typically from the web or local user context. Successful exploitation could result in unauthorized configuration changes or data exposure, depending on the plugin’s capabilities.
OpenCVE Enrichment