CVE-2023-48738: Portotheme Functionality

Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Porto Theme Porto Theme - Functionality.This issue affects Porto Theme - Functionality: from n/a before 2.12.1.

Affected products

  • Portotheme Functionality: before 2.12.1 (fixed in 2.12.1)

Published 2023-12-19. Last modified 2026-06-17.