Skip to main content

Vendor/product archive

theme-fusion / avada CVEs

Beta · best-effort

19 CVEs tagged to theme-fusion / avada2 Critical, 7 High, 10 Medium, 0 Low, 0 Unrated.

CVE-2025-64634

Published Dec 16, 2025

Missing Authorization vulnerability in ThemeFusion Avada avada allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Avada: from n/a through <= 7.13.2.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-13346

Published Feb 13, 2025

The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 7.11.13. This is d…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2024-54357

Published Dec 16, 2024

Cross-Site Request Forgery (CSRF) vulnerability in ThemeFusion Avada avada.This issue affects Avada: from n/a through <= 7.11.10.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5628

Published Sep 13, 2024

The Avada | Website Builder For WordPress & eCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's fusion_button shortcode in all versions up…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-39312

Published Jun 19, 2024

Missing Authorization vulnerability in ThemeFusion Avada.This issue affects Avada: from n/a through 7.11.1.

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-39922

Published Jun 19, 2024

Missing Authorization vulnerability in ThemeFusion Avada.This issue affects Avada: from n/a through 7.11.1.

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-2344

Published Apr 9, 2024

The Avada theme for WordPress is vulnerable to SQL Injection via the 'entry' parameter in all versions up to, and including, 7.11.6 due to insufficient escaping on the user suppli…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-2343

Published Apr 9, 2024

The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.11.6 via the form_…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-2340

Published Apr 9, 2024

The Avada theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.11.6 via the '/wp-content/uploads/fusion-forms/' directory. T…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-2311

Published Apr 9, 2024

The Avada theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 7.11.6 due to insufficient input sanit…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-39313

Published Mar 28, 2024

Server-Side Request Forgery (SSRF) vulnerability in ThemeFusion Avada.This issue affects Avada: from n/a through 7.11.1.

CVSS 7.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-39307

Published Mar 26, 2024

Unrestricted Upload of File with Dangerous Type vulnerability in ThemeFusion Avada.This issue affects Avada: from n/a through 7.11.1.

CVSS 8.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-1668

Published Mar 13, 2024

The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Sensitive Information Exposure in versions up to and including 7.11.5 via the form ent…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1468

Published Feb 29, 2024

The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajax_import_options(…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-36711

Published Jun 7, 2023

The Avada theme for WordPress is vulnerable to Stored Cross-Site Scripting via the update_layout function in versions up to, and including, 6.2.3 due to insufficient input sanitiz…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-41996

Published Oct 27, 2022

Cross-Site Request Forgery (CSRF) vulnerability in ThemeFusion Avada premium theme versions <= 7.8.1 on WordPress leading to arbitrary plugin installation/activation.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-19 of 19 CVEsPage 1 of 1