CVE-2026-42415: P-Themes Porto Theme - Functionality

Critical severity, CVSS 9.3. EPSS: 0.2% chance of exploitation in the next 30 days.

Unauthenticated SQL Injection in Porto Theme - Functionality <= 3.9.3 versions.

Affected products

  • P-Themes Porto Theme - Functionality: up to and including 3.9.3

Published 2026-10-06. Last modified 2026-10-06.