📦 Avada

by Theme Fusion

🔍 What is Avada?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-39312

CRITICAL CVSS 9.1 Jun 19, 2024

This CVE describes a missing authorization vulnerability in the Avada WordPress theme that allows authenticated users with author-level permissions to perform unrestricted ZIP file extraction. Attacke...

CVE-2022-1386

CRITICAL CVSS 9.8 May 16, 2022

This vulnerability in the Fusion Builder WordPress plugin (used by Avada theme) allows attackers to make arbitrary HTTP requests from the vulnerable server. The server-side request forgery (SSRF) flaw...

CVE-2024-13346

HIGH CVSS 7.3 Feb 13, 2025

This vulnerability allows unauthenticated attackers to execute arbitrary shortcodes in the Avada WordPress theme, potentially leading to remote code execution or data manipulation. It affects all Avad...

CVE-2024-2344

HIGH CVSS 7.2 Apr 9, 2024

The Avada WordPress theme contains a SQL injection vulnerability in the 'entry' parameter that allows authenticated attackers with editor-level permissions or higher to execute arbitrary SQL queries. ...

CVE-2024-1468

HIGH CVSS 8.8 Feb 29, 2024

The Avada WordPress theme has a vulnerability that allows authenticated attackers with contributor-level access or higher to upload arbitrary files due to missing file type validation. This can lead t...

CVE-2024-54357

MEDIUM CVSS 4.3 Dec 16, 2024

A Cross-Site Request Forgery (CSRF) vulnerability in the Avada WordPress theme allows attackers to trick authenticated administrators into performing unintended actions. This affects all Avada install...

CVE-2024-5628

MEDIUM CVSS 6.4 Sep 13, 2024

The Avada WordPress plugin has a stored XSS vulnerability in its fusion_button shortcode that allows authenticated attackers with contributor-level access or higher to inject malicious scripts into we...

CVE-2023-39922

MEDIUM CVSS 4.3 Jun 19, 2024

This CVE describes a missing authorization vulnerability in the Avada WordPress theme that allows authenticated users to perform actions they shouldn't be authorized for. It affects all Avada installa...