{"error":0,"message":null,"data":{"name":"Avada","theme":"avada","link":"https:\/\/themeforest.net\/item\/avada-responsive-multipurpose-theme\/2833226","latest":null,"closed":null,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"4b1ab3ad38dc160b55a9a455c49b8cf0101ce228c430e5b4c12d8283e3456a39","name":"Avada [avada] < 5.1.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.1.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2017-18607","name":"CVE-2017-18607","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2017-18607","description":"[en] The avada theme before 5.1.5 for WordPress has CSRF.","date":"2019-09-10"},{"id":"4b07aca1da78cf425ba140d15425e2840f1d5950","name":"Avada <= 5.1.4 - Cross-Site Request Forgery","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-themes\/Avada\/avada-514-cross-site-request-forgery","description":"The Avada theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.4. This is due to missing nonce validation on the fusion_builder_importer() function. This makes it possible for unauthenticated attackers to trigger the importer and upload arbitrary files via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2017-04-26"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"h","i":"h","a":"h","score":"8.8","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:H\/I:H\/A:H","score":"8.8","severity":"high","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}]}},{"uuid":"fbca54b7e10379bdc9c3fe09e6c4a7a759cad9a34f95a7ca1da53b937d2f9428","name":"Avada [avada] < 5.1.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.1.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2017-18606","name":"CVE-2017-18606","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2017-18606","description":"[en] The avada theme before 5.1.5 for WordPress has stored XSS.","date":"2019-09-10"},{"id":"7b4c059a178fd61346d7ec60e09cf391b55d901c","name":"Avada <= 5.1.4 - Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-themes\/Avada\/avada-514-stored-cross-site-scripting","description":"The Avada theme for WordPress is vulnerable to Stored Cross-Site Scripting via avada_portfolio_category_slug parameter saved by the save_permalink_settings() function called via 'admin_init' in versions up to 5.1.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2017-04-26"},{"id":"acad98b6-510e-47df-a264-b1412330ebec","name":"Avada Theme &lt;= 5.1.4 - Stored Cross-Site Scripting (XSS) &amp; CSRF","link":"https:\/\/wpscan.com\/vulnerability\/acad98b6-510e-47df-a264-b1412330ebec","description":"The Avada WordPress theme was affected by a Stored Cross-Site Scripting (XSS) &amp; CSRF  security vulnerability.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"f6f085ccc12cbf33d07bda1a8b2485b5fa532f686080351698c9b83932cb977d","name":"Avada [avada] < 3.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2014-9735","name":"CVE-2014-9735","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2014-9735","description":"[en] The ThemePunch Slider Revolution (revslider) plugin before 3.0.96 for WordPress and Showbiz Pro plugin 1.7.1 and earlier for Wordpress does not properly restrict access to administrator AJAX functionality, which allows remote attackers to (1) upload and execute arbitrary files via an update_plugin action; (2) delete arbitrary sliders via a delete_slider action; and (3) create, (4) update, (5) import, or (6) export arbitrary sliders via unspecified vectors.","date":"2015-06-30"},{"id":"e8a8e1c6-2c43-487a-9f11-6abd5ce6d82d","name":"WordPress Slider Revolution Shell Upload","link":"https:\/\/wpscan.com\/vulnerability\/e8a8e1c6-2c43-487a-9f11-6abd5ce6d82d","description":"Note: The Construct, Echelon, Fusion, Method, Modular and Myriad affected themes are from the Mysitemyway, who went out of business, and the themes have been forked by BackStop Themes who does not use Revslider","date":null}],"impact":{"cvss":{"version":null,"vector":null,"av":null,"ac":null,"pr":null,"ui":null,"s":null,"c":null,"i":null,"a":null,"score":"0.0","severity":null,"exploitable":"0.0","impact":"0.0"}}},{"uuid":"46e2bf55d8a18717873aa638d347a4a4e460c655a01abd70908445266e7f8b74","name":"Avada [avada] < 3.4 (unfixed)","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.4","max_operator":"lt","unfixed":"1","closed":"0"},"source":[{"id":"CVE-2015-1579","name":"CVE-2015-1579","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2015-1579","description":"Directory traversal vulnerability in the Elegant Themes Divi theme for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the img parameter in a revslider_show_image action to wp-admin\/admin-ajax.php.  NOTE: this vulnerability may be a duplicate of CVE-2014-9734.","date":"2015-02-11"},{"id":"4b077805-5dc0-4172-970e-cc3d67964f80","name":"WordPress Slider Revolution - Local File Disclosure","link":"https:\/\/wpscan.com\/vulnerability\/4b077805-5dc0-4172-970e-cc3d67964f80","description":"Note: The Construct, Echelon, Fusion, Method, Modular and Myriad affected themes are from the Mysitemyway, who went out of business, and the themes have been forked by BackStop Themes who does not use Revslider.","date":"2015-02-11"}],"impact":{"cvss":{"version":null,"vector":null,"av":null,"ac":null,"pr":null,"ui":null,"s":null,"c":null,"i":null,"a":null,"score":"0.0","severity":null,"exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-22","name":"Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","description":"The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory."}]}},{"uuid":"048ef03293a8998fc057741020c57adaefd4952d6ce90c78235b0c49c7f2d7f1","name":"Avada [avada] < 6.2.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.2.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"ca223dd30047b2d59f13febf74fbaf1ab88abf1c","name":"WordPress Avada premium theme <= 6.2.2 - Arbitrary Post Creation, Edition and Deletion vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/theme\/avada\/vulnerability\/wordpress-avada-premium-theme-6-2-2-arbitrary-post-creation-edition-and-deletion-vulnerability","description":"Arbitrary Post Creation, Edition, and Deletion vulnerability discovered by NinTechNet in WordPress Avada premium theme (versions <= 6.2.2).","date":"2020-05-01"}],"impact":[]},{"uuid":"499581e4e56340eb39c04cb88cc2351b6aa512ca288ee43909ee3070a2a1b802","name":"Avada [avada] < 6.2.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.2.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"7f9b82df222184e579bf4413d799b5e19b782775","name":"WordPress Avada premium theme <= 6.2.2 - Stored Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/theme\/avada\/vulnerability\/wordpress-avada-premium-theme-6-2-2-stored-cross-site-scripting-xss-vulnerability","description":"Stored Cross-Site Scripting (XSS) vulnerability discovered by NinTechNet in WordPress Avada premium theme (versions <= 6.2.2).","date":"2020-05-01"}],"impact":[]},{"uuid":"fb7ce7788d2c2fb855974a4b4b0ed302514bc4e1d5e2afaf8893037a93853238","name":"Avada [avada] < 7.6.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.6.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-1386","name":"CVE-2022-1386","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-1386","description":"[en] The Fusion Builder WordPress plugin before 3.6.2, used in the Avada theme, does not validate a parameter in its forms which could be used to initiate arbitrary HTTP requests. The data returned is then reflected back in the application's response. This could be used to interact with hosts on the server's local network bypassing firewalls and access control measures.","date":"2022-05-16"},{"id":"757ffabd3fd8dc108aa5a6f5ccbe305bde935aea","name":"WordPress Avada premium theme <= 7.6.1 - Unauthenticated Server-Side Request Forgery (SSRF) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/theme\/avada\/vulnerability\/wordpress-avada-premium-theme-7-6-1-unauthenticated-server-side-request-forgery-ssrf-vulnerability","description":"Unauthenticated Server-Side Request Forgery (SSRF) vulnerability discovered by Calum Elrick in WordPress Avada premium theme (versions <= 7.6.1).<br \/>\nUpdate the WordPress Avada premium theme to the latest available version (at least 7.6.2).<br \/>\n","date":"2022-04-19"},{"id":"868b652d6105affb1854e518c86343395803717a","name":"Fusion Builder <= 3.6.1 & Avada <= 7.6.1  - Unauthenticated Server-Side Request Forgery","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/detail\/fusion-builder-361-avada-761-unauthenticated-server-side-request-forgery","description":"The Fusion Builder plugin for WordPress, an Avada theme core plugin, is vulnerable to Server-Side Request Forgery in versions up to 3.6.2 along with the Avada theme in versions up to 7.6.2. This is due to insufficient validation in one of its form parameters. This makes it possible for unauthenticated attackers to interact with internal network hosts via specially crafted requests and can lead to sensitive information disclosure on certain configurations such as AWS.","date":"2022-04-19"},{"id":"bf7034ab-24c4-461f-a709-3f73988b536b","name":"Fusion Builder &lt; 3.6.2 - Unauthenticated SSRF","link":"https:\/\/wpscan.com\/vulnerability\/bf7034ab-24c4-461f-a709-3f73988b536b","description":"The plugin, used in the Avada theme, does not validate a parameter in its forms which could be used to initiate arbitrary HTTP requests. The data returned is then reflected back in the application&#039;s response. This could be used to interact with hosts on the server&#039;s local network bypassing firewalls and access control measures.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"9.8","severity":"c","exploitable":"3.9","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"9.8","severity":"critical","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"3.9","impact":"5.9"},"cwe":[{"cwe":"CWE-918","name":"Server-Side Request Forgery (SSRF)","description":"The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination."}]}},{"uuid":"2d09f83cc85f423b840d7128329d1d972adeeff9923690e60a58c3d890dd0eb5","name":"Avada [avada] < 7.8.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.8.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-41996","name":"CVE-2022-41996","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-41996","description":"[en] Cross-Site Request Forgery (CSRF) vulnerability in ThemeFusion Avada premium theme versions <= 7.8.1 on WordPress leading to arbitrary plugin installation\/activation.","date":"2022-10-27"},{"id":"72002e00a7cdcbb8fd015d536e7f258dc7c162a4","name":"WordPress Avada premium theme <= 7.8.1 - Cross-Site Request Forgery (CSRF) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/theme\/avada\/vulnerability\/wordpress-avada-premium-theme-7-8-1-cross-site-request-forgery-csrf-vulnerability","description":"Cross-Site Request Forgery (CSRF) vulnerability Leading to Arbitrary Plugin Installation\/Activation discovered by Dave Jong (Patchstack) in WordPress Avada theme (versions <= 7.8.1).\nUpdate the WordPress Avada theme to the latest available version (at least 7.8.2).","date":"2022-10-20"},{"id":"315e869e3a613029f7604c40927402929347957e","name":"Avada <= 7.8.1 - Cross-Site Request Forgery","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-themes\/Avada\/avada-781-cross-site-request-forgery","description":"The Avada theme for WordPress is vulnerable to Cross-Site Request forgery in versions up to, and including, 7.8.1 in class-avada-admin.php. This allows unauthenticated attackers to perform actions on behalf of an administrator if they can trick that administrator into performing an action, such as clicking a link.","date":"2022-09-21"},{"id":"6c977bb4-daeb-42ef-b638-f4d323f18d66","name":"Avada &lt; 7.8.2 - Arbitrary Plugin Instalation\/Activation via CRSF","link":"https:\/\/wpscan.com\/vulnerability\/6c977bb4-daeb-42ef-b638-f4d323f18d66","description":"The theme does not have CSRF check when installing and activating plugins, which could allow attackers to make logged admins install and activate arbitrary plugins via CSRF attacks","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"h","i":"h","a":"h","score":"8.8","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:H\/I:H\/A:H","score":"8.8","severity":"high","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"4420d289cf46c004c5991bcdfc85491a99c0f6e69a732ef2de346de2dbd8c38d","name":"Avada [avada] < 7.4.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.4.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"b3dfa513b1d53f0c59dcdcc3245e73aa16c4bf95","name":"Avada <= 7.4.1 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-themes\/Avada\/avada-741-reflected-cross-site-scripting","description":"The Avada theme for WordPress is vulnerable to Reflected Cross-Site Scripting via improper escaping of bbPress searches in versions up to, and including, 7.4.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"2021-09-10"}],"impact":[]},{"uuid":"bc29f60f8c2f1c82e690bbefca8df04cc2ef6c128c11da0f7cbf6a47053bbe90","name":"Avada [avada] < 7.4.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.4.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"e2e95b0e2df2badb248dfd1b48ad5a06b81da5cc","name":"Avada <= 7.4.1 - Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-themes\/Avada\/avada-741-stored-cross-site-scripting","description":"The Avada plugin for WordPress is vulnerable to Stored Cross-Site Scripting via improper escaping of HTML form entries in the backend in versions up to, and including, 7.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2021-09-10"}],"impact":[]},{"uuid":"54e6baba7a55cb4951c2e36ab0263853af8f8c1016b4385fba79da0955c4aff7","name":"Avada [avada] < 6.2.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.2.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"80c538d903e43d965e38cba58abc17271035710c","name":"404 Page Not Found","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-themes\/Avada\/avada-622-cross-site-scripting","description":"","date":null}],"impact":[]},{"uuid":"b32dce8ca664814f1a298a6ea2085fe6edeae9592394a9117b171eb7166f2be5","name":"Avada [avada] < 6.2.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.2.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2020-36711","name":"CVE-2020-36711","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2020-36711","description":"[en] The Avada theme for WordPress is vulnerable to Stored Cross-Site Scripting via the update_layout function in versions up to, and including, 6.2.3 due to insufficient input sanitization and output escaping. This makes it possible for contributor-level attackers, and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2023-06-07"},{"id":"426218734c4f4ec211dcc4378c50d914e59c9724","name":"Avada  <= 6.2.2 - Authenticated (Contributor+) Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-themes\/Avada\/avada-622-authenticated-contributor-cross-site-scripting","description":"The Avada theme for WordPress is vulnerable to Stored Cross-Site Scripting via the update_layout function in versions up to, and including, 6.2.3 due to insufficient input sanitization and output escaping. This makes it possible for contributor-level attackers, and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2020-04-24"},{"id":"ed51f0b3-1e8a-438b-9236-779a9b1cdb9f","name":"Avada &lt; 6.2.3 - Missing Permission Checks leading to Arbitrary Post Creation, Edition, Deletion and Stored XSS","link":"https:\/\/wpscan.com\/vulnerability\/ed51f0b3-1e8a-438b-9236-779a9b1cdb9f","description":"NinTechNet disclosed multiple security vulnerabilities affecting the premium Avada WordPress theme on their blog after responsibly disclosing the security vulnerabilities to Avada.\r\n\r\nThese vulnerabilities included:\r\n\r\n- Content Injection &amp; Stored XSS\r\n- Arbitrary Post Deletion\r\n- Arbitrary Post Creation\r\n\r\nThese vulnerabilities were reportedly fixed in Avada version 6.2.3, released on April 24th 2020.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"6.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"f70b884d51abc23c68e3a8365c2c6d7d7fce5cd562ba6bcc20aded0a75c05994","name":"Avada [avada] < 7.11.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.11.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-39313","name":"CVE-2023-39313","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-39313","description":"[en] Server-Side Request Forgery (SSRF) vulnerability in ThemeFusion Avada.This issue affects Avada: from n\/a through 7.11.1.","date":"2024-03-28"},{"id":"4c4901bc032cb0590682074bd57a18d35df3b934","name":"WordPress  Avada Theme  <= 7.11.1 is vulnerable to Server Side Request Forgery (SSRF)","link":"https:\/\/patchstack.com\/database\/wordpress\/theme\/avada\/vulnerability\/wordpress-avada-theme-7-11-1-authenticated-server-side-request-forgery-ssrf-vulnerability","description":"Update the WordPress Avada theme to the latest available version (at least 7.11.2).\nRafie Muhammad (Patchstack) discovered and reported this Server Side Request Forgery (SSRF) vulnerability in WordPress Avada Theme. This could allow a malicious actor to cause a website to execute website requests to an arbitrary domain of the attacker. This could allow a malicious actor to find sensitive information of other services running on the system. This vulnerability has been fixed in version 7.11.2.","date":"2023-08-10"},{"id":"e3b01543f7eed07914374661a87d33eda6e5c015","name":"Avada <= 7.11.1 - Authenticated(Contributor+) Server Side Request Forgery via 'ajax_import_options'","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-themes\/Avada\/avada-7111-authenticatedcontributor-server-side-request-forgery-via-ajax-import-options","description":"The Avada theme for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 7.11.1 via the 'ajax_import_options' function. This can allow authenticated attackers with contributor privileges to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.","date":"2023-08-10"},{"id":"c96207a7-d46a-447b-bace-d909cc7e204b","name":"Avada &lt; 7.11.2 - Contributor+ SSRF","link":"https:\/\/wpscan.com\/vulnerability\/c96207a7-d46a-447b-bace-d909cc7e204b","description":"The theme does not validate a parameter before making a request to it, which could allow users with a role as low as Contributor to perform SSRF attacks","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"h","i":"n","a":"n","score":"7.7","severity":"h","exploitable":"3.1","impact":"4.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:H\/I:N\/A:N","score":"7.7","severity":"high","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"high","i":"none","a":"none","exploitable":"3.1","impact":"4.0"},"cwe":[{"cwe":"CWE-918","name":"Server-Side Request Forgery (SSRF)","description":"The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"22108e42d0bcd66e099afc59913e048e1bb00a14c4ef6558a66e9d9dbc33185d","name":"Avada [avada] < 7.11.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.11.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-39307","name":"CVE-2023-39307","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-39307","description":"[en] Unrestricted Upload of File with Dangerous Type vulnerability in ThemeFusion Avada.This issue affects Avada: from n\/a through 7.11.1.","date":"2024-03-26"},{"id":"5b3d2154d24685b95ef9981d8c9a73d4b7fdc6d4","name":"WordPress  Avada Theme  <= 7.11.1 is vulnerable to Arbitrary File Upload","link":"https:\/\/patchstack.com\/database\/wordpress\/theme\/avada\/vulnerability\/wordpress-avada-theme-7-11-1-authenticated-arbitrary-file-upload-vulnerability","description":"Update the WordPress Avada theme to the latest available version (at least 7.11.2).\nRafie Muhammad (Patchstack) discovered and reported this Arbitrary File Upload vulnerability in WordPress Avada Theme. This could allow a malicious actor to upload any type of file to your website. This can include backdoors which are then executed to gain further access to your website. This vulnerability has been fixed in version 7.11.2.","date":"2023-08-10"},{"id":"7034c930b1b9ab9913df54da3804869c4795d1e3","name":"Avada <= 7.11.1 - Authenticated(Contributor+) Arbitrary File Upload via 'ajax_import_options'","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-themes\/Avada\/avada-7111-authenticatedcontributor-arbitrary-file-upload-via-ajax-import-options","description":"The Avada theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'ajax_import_options' function in versions up to, and including, 7.11.1. This makes it possible for authenticated attackers with contributor permissions to upload arbitrary files on the affected site's server which may make remote code execution possible if they are able to successfully exploit a race condition.","date":"2023-08-10"},{"id":"81108b5a-d3e0-43f4-b2c6-9a2613e46052","name":"Avada &lt; 7.11.2 - Subscriber+ Portfolio Permalinks Creation","link":"https:\/\/wpscan.com\/vulnerability\/81108b5a-d3e0-43f4-b2c6-9a2613e46052","description":"The theme is vulnerable to unauthorized modification of data due to a missing capability check, allowing any authenticated attackers, with such as subscriber and above, to save Portfolio permalinks.","date":null},{"id":"6a819332-0b24-40f6-9cc5-06712dd1595b","name":"Avada &lt; 7.11.2 - Contributor+ Arbitrary File Upload","link":"https:\/\/wpscan.com\/vulnerability\/6a819332-0b24-40f6-9cc5-06712dd1595b","description":"The theme is vulnerable to arbitrary file uploads due to missing file type validation in the &#039;ajax_import_options&#039; function, making it possible for authenticated attackers with contributor permissions to upload arbitrary files on the affected site&#039;s server which may make remote code execution possible if they can successfully exploit a race condition.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:L\/UI:N\/S:C\/C:H\/I:H\/A:H","av":"n","ac":"h","pr":"l","ui":"n","s":"c","c":"h","i":"h","a":"h","score":"8.5","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:L\/UI:N\/S:C\/C:H\/I:H\/A:H","score":"8.5","severity":"high","av":"network","ac":"high","pr":"low","ui":"none","s":"changed","c":"high","i":"high","a":"high","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-434","name":"Unrestricted Upload of File with Dangerous Type","description":"The product allows the upload or transfer of dangerous file types that are automatically processed within its environment."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"8e96f05ba87bfe882122f23d51e7aeb5a47733d11b6029ebd018d18b4ae53641","name":"Avada [avada] < 7.11.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.11.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-39312","name":"CVE-2023-39312","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-39312","description":"[en] Missing Authorization vulnerability in ThemeFusion Avada.This issue affects Avada: from n\/a through 7.11.1.","date":"2024-06-19"},{"id":"3044500677d765ee07b08c51e2eb4004ffe933b0","name":"WordPress  Avada Theme  <= 7.11.1 is vulnerable to Arbitrary File Upload","link":"https:\/\/patchstack.com\/database\/wordpress\/theme\/avada\/vulnerability\/wordpress-avada-theme-7-11-1-authenticated-author-unrestricted-zip-extraction-vulnerability","description":"Update the WordPress Avada theme to the latest available version (at least 7.11.2).\nRafie Muhammad (Patchstack) discovered and reported this Arbitrary File Upload vulnerability in WordPress Avada Theme. This could allow a malicious actor to upload any type of file to your website. This can include backdoors which are then executed to gain further access to your website. This vulnerability has been fixed in version 7.11.2.","date":"2023-08-10"},{"id":"bed644df589e23b17bcbcad0474a1d3006989244","name":"Avada <= 7.11.1 - Authenticated(Author+) Arbitrary File Upload via Zip Extraction","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-themes\/Avada\/avada-7111-authenticatedauthor-arbitrary-file-upload-via-zip-extraction","description":"The Avada theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation when extracting zip files in the 'process_upload' and 'regenerate_icon_files' functions in versions up to, and including, 7.11.1. This makes it possible for authenticated attackers with author permissions to upload arbitrary files on the affected site's server which may make remote code execution possible.","date":"2023-08-10"},{"id":"d90338e3-90fa-46be-8fa8-182d1249cc7c","name":"Avada &lt; 7.11.2 - Author+ Arbitrary File Upload via Zip Extraction","link":"https:\/\/wpscan.com\/vulnerability\/d90338e3-90fa-46be-8fa8-182d1249cc7c","description":"The theme is vulnerable to arbitrary file uploads due to missing file type validation when extracting zip files in the &#039;process_upload&#039; and &#039;regenerate_icon_files&#039; functions. This makes it possible for authenticated attackers with author permissions to upload arbitrary files on the affected site&#039;s server which may make remote code execution possible","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:C\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"h","ui":"n","s":"c","c":"h","i":"h","a":"h","score":"9.1","severity":"c","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:C\/C:H\/I:H\/A:H","score":"9.1","severity":"critical","av":"network","ac":"low","pr":"high","ui":"none","s":"changed","c":"high","i":"high","a":"high","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"3b534ea111b9b4cc4ba3ee27a235d53d2b5e944d9b7b2e14beefce62170bef65","name":"Avada [avada] < 7.11.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.11.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-39922","name":"CVE-2023-39922","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-39922","description":"[en] Missing Authorization vulnerability in ThemeFusion Avada.This issue affects Avada: from n\/a through 7.11.1.","date":"2024-06-19"},{"id":"039bf122ec0cef5cb94584697c03ddf8071e9201","name":"WordPress  Avada Theme  <= 7.11.1 is vulnerable to Broken Access Control","link":"https:\/\/patchstack.com\/database\/wordpress\/theme\/avada\/vulnerability\/wordpress-avada-theme-7-11-1-authenticated-broken-access-control-vulnerability","description":"Update the WordPress Avada theme to the latest available version (at least 7.11.2).\nRafie Muhammad (Patchstack) discovered and reported this Broken Access Control vulnerability in WordPress Avada Theme. A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action. This vulnerability has been fixed in version 7.11.2.","date":"2023-08-10"},{"id":"48193fa37cb7921b0d91f02c2fc086a3c6cb31da","name":"Avada <= 7.11.1 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-themes\/Avada\/avada-7111-missing-authorization","description":"The Avada theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on an unknown function in versions up to, and including, 7.11.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to save Portfolio permalinks.","date":"2023-08-10"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"ab819f2faf5bf2a15b8062de8aa071ea6b1e4092bd86dc86e3c74168d2f8883c","name":"Avada [avada] < 7.4.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.4.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"8a05ff50-ed05-402f-a1c9-b611dff80d76","name":"Avada &lt; 7.4.2 - Stored Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/8a05ff50-ed05-402f-a1c9-b611dff80d76","description":"The Avada Forms component allowed unescaped HTML form entries to be loaded on the backend.","date":null}],"impact":[]},{"uuid":"997d5173238c0e71c09bedfc16b485b9655dfac5fcdcf66e8a67edbeb6369519","name":"Avada [avada] < 7.4.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.4.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"eb172b07-56ab-41ce-92a1-be38bab567cb","name":"Avada &lt; 7.4.2 - Reflected Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/eb172b07-56ab-41ce-92a1-be38bab567cb","description":"The theme does not properly escape bbPress searches before outputting them back as breadcrumbs, leading to a Reflected Cross-Site Scripting issue.","date":null}],"impact":[]},{"uuid":"57790ac8a2f30fb63462069b09b8a1d9769252cf751c9d683260a7d68edaa521","name":"Avada [avada] < 7.11.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.11.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-1468","name":"CVE-2024-1468","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-1468","description":"[en] The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajax_import_options() function in all versions up to, and including, 7.11.4. This makes it possible for authenticated attackers, with contributor-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.","date":"2024-02-29"},{"id":"3115906b01481bdf27812bee0f5eda2fb087246e","name":"Avada | Website Builder For WordPress & WooCommerce <= 7.11.4 - Authenticated (Contributor+) Arbitrary File Upload","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-themes\/Avada\/avada-website-builder-for-wordpress-woocommerce-7114-authenticated-contributor-arbitrary-file-upload","description":"The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajax_import_options() function in all versions up to, and including, 7.11.4. This makes it possible for authenticated attackers, with contributor-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.","date":"2024-02-28"},{"id":"2ba1f89092817acd9347870fecb8408589070f5e","name":"WordPress  Avada Theme    <= 7.11.4 is vulnerable to Arbitrary File Upload","link":"https:\/\/patchstack.com\/database\/wordpress\/theme\/avada\/vulnerability\/wordpress-avada-theme-7-11-4-authenticated-contributor-arbitrary-file-upload-vulnerability","description":"Update the WordPress Avada theme to the latest available version (at least 7.11.5).\nMuhammad Zeeshan (Xib3rR4dAr) discovered and reported this Arbitrary File Upload vulnerability in WordPress Avada Theme. This could allow a malicious actor to upload any type of file to your website. This can include backdoors which are then executed to gain further access to your website. This vulnerability has been fixed in version 7.11.5.\nHave additional information or questions about this entry? Get in touch.","date":null},{"id":"df0d86aa-ddba-4d5f-8d8e-a0460c0cd079","name":"Avada | Website Builder For WordPress &amp; WooCommerce &lt; 7.11.5 - Authenticated (Contributor+) Arbitrary File Upload","link":"https:\/\/wpscan.com\/vulnerability\/df0d86aa-ddba-4d5f-8d8e-a0460c0cd079","description":"The Avada | Website Builder For WordPress &amp; WooCommerce theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajax_import_options() function in all versions up to, and including, 7.11.4. This makes it possible for authenticated attackers, with contributor-level access and above, to upload arbitrary files on the affected site&#039;s server which may make remote code execution possible.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"8.8","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"8.8","severity":"high","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-434","name":"Unrestricted Upload of File with Dangerous Type","description":"The product allows the upload or transfer of dangerous file types that are automatically processed within its environment."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"513e246625cfdf3330e5d5e63b07776eff424a81a9a5eb2aa0800ed106769977","name":"Avada [avada] < 7.11.7","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.11.7","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-2311","name":"CVE-2024-2311","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-2311","description":"[en] The Avada theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 7.11.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-04-09"},{"id":"e0e7512b50c8899dd37e5b0fab2674d4b6ae8e3a","name":"Avada <= 7.11.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-themes\/Avada\/avada-7116-authenticated-contributor-stored-cross-site-scripting-via-shortcode","description":"The Avada theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 7.11.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-03-20"},{"id":"013317ffc9842985ed5069e6a2f968689829e74d","name":"WordPress  Avada Theme    <= 7.11.6 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/theme\/avada\/vulnerability\/wordpress-avada-theme-7-11-6-authenticated-contributor-stored-cross-site-scripting-via-shortcode-vulnerability","description":"Update the WordPress Avada theme to the latest available version (at least 7.11.7).\nMuhammad Zeeshan (Xib3rR4dAr) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Avada Theme. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 7.11.7.\nHave additional information or questions about this entry? Get in touch.","date":null},{"id":"a543a7e4-16f2-4691-9f19-575604edad79","name":"Avada &lt; 7.11.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode","link":"https:\/\/wpscan.com\/vulnerability\/a543a7e4-16f2-4691-9f19-575604edad79","description":"The Avada theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin&#039;s shortcodes in all versions up to, and including, 7.11.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"8a1665b88c462213b74e0211c167f78c7c87e3a63d73be25db549153ac04f3e9","name":"Avada [avada] < 7.11.7","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.11.7","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-2340","name":"CVE-2024-2340","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-2340","description":"[en] The Avada theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.11.6 via the '\/wp-content\/uploads\/fusion-forms\/' directory. This makes it possible for unauthenticated attackers to extract sensitive data uploaded via an Avada created form with a file upload mechanism.","date":"2024-04-09"},{"id":"588e1c76efa6b07c45590b3640fd34c2718a8e12","name":"Avada <= 7.11.6 - Unauthenticated Sensitive Information Exposure via Form Uploads Directory Listing","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-themes\/Avada\/avada-7116-unauthenticated-sensitive-information-exposure-via-form-uploads-directory-listing","description":"The Avada theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.11.6 via the '\/wp-content\/uploads\/fusion-forms\/' directory. This makes it possible for unauthenticated attackers to extract sensitive data uploaded via an Avada created form with a file upload mechanism.","date":"2024-03-20"},{"id":"763e45c92497209c6958be43315c7284078a3ae5","name":"WordPress  Avada Theme    <= 7.11.6 is vulnerable to Sensitive Data Exposure","link":"https:\/\/patchstack.com\/database\/wordpress\/theme\/avada\/vulnerability\/wordpress-avada-theme-7-11-6-unauthenticated-sensitive-information-exposure-via-form-uploads-directory-listing-vulnerability","description":"Update the WordPress Avada theme to the latest available version (at least 7.11.7).\nMuhammad Zeeshan (Xib3rR4dAr) discovered and reported this Sensitive Data Exposure vulnerability in WordPress Avada Theme.  This vulnerability has been fixed in version 7.11.7.\nHave additional information or questions about this entry? Get in touch.","date":null},{"id":"507e1d07-4953-4a31-81e8-80f01f971e2a","name":"Avada &lt; 7.11.7 - Unauthenticated Sensitive Information Exposure via Form Uploads Directory Listing","link":"https:\/\/wpscan.com\/vulnerability\/507e1d07-4953-4a31-81e8-80f01f971e2a","description":"The Avada theme for WordPress is vulnerable to Sensitive Information Exposure via the &#039;\/wp-content\/uploads\/fusion-forms\/&#039; directory. This makes it possible for unauthenticated attackers to extract sensitive data uploaded via an Avada created form with a file upload mechanism.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"5.3","severity":"m","exploitable":"3.9","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"3.9","impact":"1.4"},"cwe":[{"cwe":"CWE-548","name":"Exposure of Information Through Directory Listing","description":"The product inappropriately exposes a directory listing with an index of all the resources located inside of the directory."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"e279ba3ac6be72b6f2ea329f4ad0c075b914c2c362a408604716d572471ce999","name":"Avada [avada] < 7.11.7","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.11.7","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-2343","name":"CVE-2024-2343","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-2343","description":"[en] The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.11.6 via the form_to_url_action function. This makes it possible for authenticated attackers, with contributor-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.","date":"2024-04-09"},{"id":"be98017d795dd3719ef956b1fdf200aef5977927","name":"Avada <= 7.11.6 - Authenticated (Contributor+) Server-Side Request Forgery via form_to_url_action","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-themes\/Avada\/avada-7116-authenticated-contributor-server-side-request-forgery-via-form-to-url-action","description":"The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.11.6 via the form_to_url_action function. This makes it possible for authenticated attackers, with contributor-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.","date":"2024-03-20"},{"id":"604d5fb47467eac9c128e4054b9c992697b418f9","name":"WordPress  Avada Theme    <= 7.11.6 is vulnerable to Server Side Request Forgery (SSRF)","link":"https:\/\/patchstack.com\/database\/wordpress\/theme\/avada\/vulnerability\/wordpress-avada-theme-7-11-6-authenticated-contributor-server-side-request-forgery-via-form-to-url-action-vulnerability","description":"Update the WordPress Avada theme to the latest available version (at least 7.11.7).\nMuhammad Zeeshan (Xib3rR4dAr) discovered and reported this Server Side Request Forgery (SSRF) vulnerability in WordPress Avada Theme. This could allow a malicious actor to cause a website to execute website requests to an arbitrary domain of the attacker. This could allow a malicious actor to find sensitive information of other services running on the system. This vulnerability has been fixed in version 7.11.7.\nHave additional information or questions about this entry? Get in touch.","date":null},{"id":"0bea7dba-886b-4363-9084-38608c49192c","name":"Avada &lt; 7.11.7 - Authenticated (Contributor+) Server-Side Request Forgery via form_to_url_action","link":"https:\/\/wpscan.com\/vulnerability\/0bea7dba-886b-4363-9084-38608c49192c","description":"The Avada | Website Builder For WordPress &amp; WooCommerce theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.11.6 via the form_to_url_action function. This makes it possible for authenticated attackers, with contributor-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"3.1","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"6.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"3.1","impact":"2.7"},"cwe":[{"cwe":"CWE-918","name":"Server-Side Request Forgery (SSRF)","description":"The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"ff1208056c19d0b647e90e483df8aca21089f64c84d3fd1bf0f9399bd8e4347b","name":"Avada [avada] < 7.11.7","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.11.7","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-2344","name":"CVE-2024-2344","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-2344","description":"[en] The Avada theme for WordPress is vulnerable to SQL Injection via the 'entry' parameter in all versions up to, and including, 7.11.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticted attackers, with editor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"2024-04-09"},{"id":"d1baa160ca1eb661e5e71c7af5fe97a2ccc43882","name":"Avada <= 7.11.6 - Authenticated (Admin+) SQL Injection via entry","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-themes\/Avada\/avada-7116-authenticated-admin-sql-injection-via-entry","description":"The Avada theme for WordPress is vulnerable to SQL Injection via the 'entry' parameter in all versions up to, and including, 7.11.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticted attackers, with editor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"2024-03-20"},{"id":"99ec36955b74a08e3cbf497968b35d77f93da99a","name":"WordPress  Avada Theme    <= 7.11.6 is vulnerable to SQL Injection","link":"https:\/\/patchstack.com\/database\/wordpress\/theme\/avada\/vulnerability\/wordpress-avada-theme-7-11-6-authenticated-admin-sql-injection-via-entry-vulnerability","description":"Update the WordPress Avada theme to the latest available version (at least 7.11.7).\nMuhammad Zeeshan (Xib3rR4dAr) discovered and reported this SQL Injection vulnerability in WordPress Avada Theme. This could allow a malicious actor to directly interact with your database, including but not limited to stealing information. This vulnerability has been fixed in version 7.11.7.\nHave additional information or questions about this entry? Get in touch.","date":null},{"id":"da6a4273-be9b-4381-b24e-4a4be2c96daa","name":"Avada &lt; 7.11.7 - Authenticated (Admin+) SQL Injection via entry","link":"https:\/\/wpscan.com\/vulnerability\/da6a4273-be9b-4381-b24e-4a4be2c96daa","description":"The Avada theme for WordPress is vulnerable to SQL Injection via the &#039;entry&#039; parameter in all versions up to, and including, 7.11.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticted attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"h","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"7.2","severity":"h","exploitable":"1.2","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"7.2","severity":"high","av":"network","ac":"low","pr":"high","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"1.2","impact":"5.9"},"cwe":[{"cwe":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","description":"The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"6127cdf909d63d0fe2d10feb73de6eb7b9e7eb3d81efde7d8aab46c9ea99fb55","name":"Avada [avada] < 7.11.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.11.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-1668","name":"CVE-2024-1668","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-1668","description":"[en] The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Sensitive Information Exposure in versions up to and including 7.11.5 via the form entries page. This makes it possible for authenticated attackers, with contributor access and above, to view the contents of all form submissions, including fields that are obfuscated (such as the contact form's \"password\" field).","date":"2024-03-13"},{"id":"0fb8ae0f4d71b23fc7a82b35c15f2cd68994e40f","name":"Avada <= 7.11.5 - Authenticated(Contributor+) Sensitive Information Exposure via Form Entries","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-themes\/fusion-builder\/avada-7115-authenticatedcontributor-sensitive-information-exposure-via-form-entries","description":"The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Sensitive Information Exposure in versions up to and including 7.11.5 via the form entries page. This makes it possible for authenticated attackers, with contributor access and above, to view the contents of all form submissions, including fields that are obfuscated (such as the contact form's \"password\" field).","date":"2024-03-01"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"6.5","severity":"m","exploitable":"2.8","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"2.8","impact":"3.6"},"cwe":[{"cwe":"CWE-284","name":"Improper Access Control","description":"The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"87c1156c8df71d2ae846935aa9577f6bd9f64725c783e0683d928ec8ffc88b5a","name":"Avada [avada] < 7.11.11","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.11.11","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-54357","name":"CVE-2024-54357","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-54357","description":"[en] Cross-Site Request Forgery (CSRF) vulnerability in ThemeFusion Avada avada.This issue affects Avada: from n\/a through <= 7.11.10.","date":"2024-12-16"},{"id":"d2bf82df3c38bf7ad72bad914467439e4468623b","name":"Avada <= 7.11.10 - Cross-Site Request Forgery","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-themes\/Avada\/avada-71110-cross-site-request-forgery","description":"The Avada theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 7.11.10. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2024-12-11"},{"id":"4cf0a31ff964a50949112e407e7342d818f987c0","name":"WordPress Avada Theme <= 7.11.10 is vulnerable to Cross Site Request Forgery (CSRF)","link":"https:\/\/patchstack.com\/database\/wordpress\/theme\/avada\/vulnerability\/wordpress-avada-theme-7-11-10-cross-site-request-forgery-csrf-vulnerability","description":"<p>WordPress Avada Theme <= 7.11.10 is vulnerable to Cross Site Request Forgery (CSRF)<\/p><p>Software: Avada<\/p><p>Fixed in version 7.11.11 <\/p><p>Affected Version <= 7.11.10<\/p><p>CVE: CVE-2024-54357<\/p>","date":"2024-12-11"},{"id":"40ca62d6-6d60-4b83-9331-0afca5636b44","name":"Avada &lt; 7.11.11 - Cross-Site Request Forgery","link":"https:\/\/wpscan.com\/vulnerability\/40ca62d6-6d60-4b83-9331-0afca5636b44","description":"The Avada theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 7.11.10. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":null},{"id":"EUVD-2024-52480","name":"EUVD-2024-52480","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2024-52480","description":"Cross-Site Request Forgery (CSRF) vulnerability in ThemeFusion Avada.This issue affects Avada: from n\/a through 7.11.10.","date":"2024-12-16"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"2.8","impact":"1.4"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"acdf29f19737132d30cc9295d4da052aaa56d3c7782748ea969352c4017e8215","name":"Avada [avada] <= 7.11.5 (unfixed)","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.11.5","max_operator":"le","unfixed":"1","closed":"0"},"source":[{"id":"1630b118c71045323c7ad7da359b9a9dde0fe1bd","name":"WordPress  Avada Theme    <= 7.11.5 is vulnerable to Sensitive Data Exposure","link":"https:\/\/patchstack.com\/database\/wordpress\/theme\/avada\/vulnerability\/wordpress-avada-plugin-7-11-5-authenticated-contributor-sensitive-information-exposure-via-form-entries-vulnerability","description":"Update the WordPress Avada theme to the latest available version (at least 7.11.6).\nMuhammad Zeeshan (Xib3rR4dAr) discovered and reported this Sensitive Data Exposure vulnerability in WordPress Avada Theme.  This vulnerability has been fixed in version 7.11.6.\nHave additional information or questions about this entry? Get in touch.","date":null}],"impact":[]},{"uuid":"664621aac3e428f2e634a7e418ccdbad34345069c9cace5d77a8503cc59c1e58","name":"Avada [avada] < 7.11.11","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.11.11","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-24748","name":"CVE-2025-24748","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-24748","description":"[en] Missing Authorization vulnerability in ThemeFusion Avada avada.This issue affects Avada: from n\/a through <= 7.11.10.","date":"2025-07-04"},{"id":"c4611940dd776c1bbcbc2c9e846868756df01812","name":"Avada <= 7.11.10 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-themes\/Avada\/avada-71110-missing-authorization","description":"The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 7.11.10. This makes it possible for unauthenticated attackers to perform an unauthorized action.","date":"2025-01-24"},{"id":"12cc81ecb2ae3c0bb24355e3a9829b047648fe14","name":"WordPress All In One Slider Responsive Plugin <= 3.7.9 is vulnerable to SQL Injection","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/all_in_one_carousel\/vulnerability\/wordpress-all-in-one-slider-responsive-plugin-3-7-9-sql-injection-vulnerability","description":"<p>WordPress All In One Slider Responsive Plugin <= 3.7.9 is vulnerable to SQL Injection<\/p><p>Software: All In One Slider Responsive<\/p><p>Fixed in version 3.8 <\/p><p>Affected Version <= 3.7.9<\/p><p>CVE: CVE-2025-24748<\/p>","date":"2025-07-04"},{"id":"5c3cbcfe-7167-49ed-83f0-afc15efb66cd","name":"Avada &lt; 7.11.11 - Missing Authorization","link":"https:\/\/wpscan.com\/vulnerability\/5c3cbcfe-7167-49ed-83f0-afc15efb66cd","description":"The Avada | Website Builder For WordPress &amp; WooCommerce theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 7.11.10. This makes it possible for unauthenticated attackers to perform an unauthorized action.","date":"2025-01-24"},{"id":"EUVD-2025-19957","name":"EUVD-2025-19957","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-19957","description":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup All In One Slider Responsive allows SQL Injection. This issue affects All In One Slider Responsive: from n\/a through 3.7.9.","date":"2025-07-04"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"5.3","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","description":"The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data."},{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"4215afa77a1197b73854df2569270f7890129406751af20c28535287d8b60273","name":"Avada [avada] < 7.11.14","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.11.14","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-13346","name":"CVE-2024-13346","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-13346","description":"[en] The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 7.11.13. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.","date":"2025-02-13"},{"id":"31ff59c7dbfff680e73480229d20ba7db809cbc1","name":"Avada Theme <= 7.11.13 - Unauthenticated Arbitrary Shortcode Execution","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-themes\/Avada\/avada-theme-71113-unauthenticated-arbitrary-shortcode-execution","description":"The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 7.11.13. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.","date":"2025-02-12"},{"id":"54e4f5f3-61fa-49e2-8c5b-f7c6a7a6d481","name":"Avada Theme &lt; 7.11.14 - Unauthenticated Arbitrary Shortcode Execution","link":"https:\/\/wpscan.com\/vulnerability\/54e4f5f3-61fa-49e2-8c5b-f7c6a7a6d481","description":"The Avada | Website Builder For WordPress &amp; WooCommerce theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 7.11.13. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.","date":"2025-02-12"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"l","a":"l","score":"7.3","severity":"h","exploitable":"3.9","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:L\/A:L","score":"7.3","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"low","a":"low","exploitable":"3.9","impact":"5.9"},"cwe":[{"cwe":"CWE-94","name":"Improper Control of Generation of Code ('Code Injection')","description":"The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"da39d5f63a91687619c189e77cbf6ef8056be7e617e76f006341137c5b609e42","name":"Avada [avada] < 7.13.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.13.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-64634","name":"CVE-2025-64634","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-64634","description":"[en] Missing Authorization vulnerability in ThemeFusion Avada avada allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Avada: from n\/a through <= 7.13.2.","date":"2025-12-16"},{"id":"f2f51ae0c000fff7181731dc38dbf44bee23582e","name":"Avada <= 7.13.2 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-themes\/Avada\/avada-7131-missing-authorization","description":"The Avada theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 7.13.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.","date":"2025-10-03"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"5.3","severity":"m","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"bbb8588158258788b27ba358108097545ac28b5e1c019a89ff22f4ccc177278f","name":"Avada [avada] < 7.13.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.13.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-58922","name":"CVE-2025-58922","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-58922","description":"[en] Cross-Site Request Forgery (CSRF) vulnerability in ThemeFusion Avada allows Cross Site Request Forgery.This issue affects Avada: from n\/a before 7.13.2.","date":"2026-04-22"},{"id":"35d1c576fc77f405e110b2dfbf6cf8dadc3acad3","name":"Avada < 7.13.2 - Cross-Site Request Forgery","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-themes\/Avada\/avada-7132-cross-site-request-forgery","description":"The Avada theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 7.13.2. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2026-04-22"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"c8f722ea816bb938c1e3e7a360d62fcfd80f9526c82fa57ce3ab49bbbb959e05","name":"Avada [avada] < 3.15.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.15.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-12256","name":"CVE-2026-12256","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-12256","description":"[en] Contributor PHP Object Injection in Avada <= 3.15.3 versions.","date":"2026-06-16"},{"id":"5668080b3fdbeb779b4f9f46f5f2caedf327e624","name":"Avada <= 3.15.3 - Authenticated (Contributor+) PHP Object Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-themes\/Avada\/avada-3153-authenticated-contributor-php-object-injection","description":"The Avada theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.15.3 via deserialization of untrusted input. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.","date":"2026-06-15"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"8.8","severity":"h","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"8.8","severity":"high","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-502","name":"Deserialization of Untrusted Data","description":"The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"1fd2348f96d4d58b3500c7b945ecc0d9365a4e9119ba6bbc66e51c10c495cc03","name":"Avada [avada] < 3.16.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.16.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"c7a89c30ac4ae0e661f870faf7a13ebbda46e0cf","name":"Avada <= 7.16 and Fusion Builder <= 3.16 - Unauthenticated Remote Code Execution via Arbitrary File Write","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/detail\/avada-716-and-fusion-builder-316-unauthenticated-remote-code-execution-via-arbitrary-file-write","description":"The Avada theme for WordPress is vulnerable to Arbitrary File Write in all versions up to, and including, 7.16 when the Fusion Builder plugin is installed and active in versions up to, and including, 3.16. This is due to a chain of authorization and input validation weaknesses across the two components that makes it possible for unauthenticated attackers to write attacker-controlled files to the server. This can be used to create and execute arbitrary PHP files, resulting in remote code execution and complete site compromise. Successful exploitation requires both Avada and Fusion Builder to be installed and active, as well as certain administrator-authored content to be present.","date":null}],"impact":[]},{"uuid":"ab612832a1930344f08da5fcb0589819c633fdd9cc5966b96d156218ff22e456","name":"Avada [avada] < 7.16.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.16.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-18431","name":"CVE-2026-18431","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-18431","description":"[en] The Avada theme for WordPress is vulnerable to Arbitrary File Write in all versions up to, and including, 7.16 when the Fusion Builder plugin is installed and active in versions up to, and including, 3.16. This is due to a chain of authorization and input validation weaknesses across the two components that makes it possible for unauthenticated attackers to write attacker-controlled files to the server. This can be used to create and execute arbitrary PHP files, resulting in remote code execution and complete site compromise. Successful exploitation requires both Avada and Fusion Builder to be installed and active, as well as certain administrator-authored content to be present.","date":"2026-08-26"},{"id":"bc78f3010b1080efb3d53026f285c7373edbab00","name":"Avada <= 7.15.6 and Fusion Builder <= 3.15.6 - Unauthenticated Arbitrary File Write via Fusion Patcher","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-themes\/Avada\/avada-7156-and-fusion-builder-3156-unauthenticated-arbitrary-file-write-via-fusion-patcher","description":"The Avada theme for WordPress is vulnerable to Arbitrary File Write in all versions up to, and including, 7.15.6 when the Fusion Builder plugin is installed and active in versions up to, and including, 3.15.6. This is due to a vulnerability chain that allows unauthenticated attackers to invoke Fusion Builder dynamic-data action hooks, override Fusion Library patch metadata for the current request, and use the Fusion Library patcher to write attacker-controlled content to an arbitrary PHP file path without a capability check, path validation, or extension validation. This makes it possible for unauthenticated attackers to write and execute arbitrary PHP files on the server. Successful exploitation requires both Avada and Fusion Builder to be active and an administrator-authored post ID, such as the default Hello World post on a stock install.","date":"2026-08-25"},{"id":"8fd6692a5053ae866eed925f196fe6b9ab0e6161","name":"Avada <= 7.15.6 and Fusion Builder <= 3.15.6 - Unauthenticated Remote Code Execution via Fusion Patcher","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/fusion-builder\/avada-7156-and-fusion-builder-3156-unauthenticated-remote-code-execution-via-fusion-patcher","description":"The Avada theme for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 7.15.6 when the Fusion Builder plugin is installed and active in versions up to, and including, 3.15.6. This is due to a vulnerability chain that allows unauthenticated attackers to invoke Fusion Builder dynamic-data action hooks, override Fusion Library patch metadata for the current request, and use the Fusion Library patcher to write attacker-controlled content to an arbitrary PHP file path without a capability check, path validation, or extension validation. This makes it possible for unauthenticated attackers to write and execute arbitrary PHP files on the server. Successful exploitation requires both Avada and Fusion Builder to be active and an administrator-authored post ID, such as the default Hello World post on a stock install.","date":"2026-08-25"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"9.8","severity":"c","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"9.8","severity":"critical","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"total","kev":false,"kev_date":null}}}]},"updated":"1787722436"}