VYPR
Medium severity4.3NVD Advisory· Published Dec 9, 2025· Updated Apr 27, 2026

CVE-2025-63067

CVE-2025-63067

Description

Missing Authorization vulnerability in p-themes Porto Theme - Functionality porto-functionality allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Porto Theme - Functionality: from n/a through < 3.7.3.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Missing authorization in Porto Theme - Functionality plugin (≤3.7.3) allows unauthenticated attackers to exploit incorrectly configured access controls.

Vulnerability

Overview

The Porto Theme - Functionality plugin for WordPress (versions through 3.7.3) contains a missing authorization vulnerability. The plugin fails to properly enforce access control checks in certain functions, allowing exploitation of incorrectly configured security levels. This is classified as a broken access control issue [1].

Exploitation

An attacker can exploit this vulnerability without requiring authentication or elevated privileges. The missing authorization check means that any unauthenticated user can trigger privileged actions that should be restricted to higher-privileged roles. This type of vulnerability is commonly used in mass-exploit campaigns targeting thousands of WordPress sites regardless of their size or popularity [1].

Impact

Successful exploitation allows an unprivileged attacker to execute higher-privileged actions within the plugin's functionality. While the severity is rated as medium (CVSS 4.3), the impact is considered low severity by the vendor, and exploitation is deemed unlikely [1].

Mitigation Mitigation

The vulnerability has been patched in version 3.7.3 of the plugin. Users are strongly advised to update immediately. Patchstack users can enable auto-updates for vulnerable plugins. If updating is not possible, contacting a hosting provider or web developer for assistance is recommended [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.