Show filters
16 Total Results
Displaying 11-16 of 16
Sort by:
Attacker Value
Unknown
CVE-2024-1468
Disclosure Date: February 29, 2024 (last updated February 06, 2025)
The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajax_import_options() function in all versions up to, and including, 7.11.4. This makes it possible for authenticated attackers, with contributor-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
0
Attacker Value
Unknown
CVE-2020-36711
Disclosure Date: June 07, 2023 (last updated October 08, 2023)
The Avada theme for WordPress is vulnerable to Stored Cross-Site Scripting via the update_layout function in versions up to, and including, 6.2.3 due to insufficient input sanitization and output escaping. This makes it possible for contributor-level attackers, and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown
CVE-2022-41996
Disclosure Date: October 20, 2022 (last updated December 22, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in ThemeFusion Avada premium theme versions <= 7.8.1 on WordPress leading to arbitrary plugin installation/activation.
0
Attacker Value
Unknown
CVE-2022-1386
Disclosure Date: May 16, 2022 (last updated March 15, 2024)
The Fusion Builder WordPress plugin before 3.6.2, used in the Avada theme, does not validate a parameter in its forms which could be used to initiate arbitrary HTTP requests. The data returned is then reflected back in the application's response. This could be used to interact with hosts on the server's local network bypassing firewalls and access control measures.
0
Attacker Value
Unknown
CVE-2017-18606
Disclosure Date: September 10, 2019 (last updated November 27, 2024)
The avada theme before 5.1.5 for WordPress has stored XSS.
0
Attacker Value
Unknown
CVE-2017-18607
Disclosure Date: September 10, 2019 (last updated November 27, 2024)
The avada theme before 5.1.5 for WordPress has CSRF.
0