Thème WordPress
Vulnérabilités Avada | Website Builder For WordPress & WooCommerce
Cette page rassemble les failles publiées pour Avada | Website Builder For WordPress & WooCommerce, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Avada | Website Builder For WordPress & WooCommerce
23 fiches
Avada <= 3.15.3 – Authenticated (Contributor+) PHP Object Injection
The Avada theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.15.3 via deserialization of untrusted input. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a…
*-3.15.3
3.15.4
15/06/2026
Avada < 7.13.2 – Cross-Site Request Forgery
The Avada theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 7.13.2. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an…
[*, 7.13.2)
7.13.2
22/04/2026
Avada <= 7.13.2 – Missing Authorization
The Avada theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 7.13.2. This makes it possible for authenticated attackers, with subscriber-level access and above,…
*-7.13.2
7.13.3
03/10/2025
Avada Theme <= 7.11.13 – Unauthenticated Arbitrary Shortcode Execution
The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 7.11.13. This is due to the software allowing users to execute an action…
*-7.11.13
7.11.14
12/02/2025
Avada <= 7.11.10 – Missing Authorization
The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 7.11.10. This makes it possible…
*-7.11.10
7.11.11
24/01/2025
Avada <= 7.11.10 – Cross-Site Request Forgery
The Avada theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 7.11.10. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to…
*-7.11.10
7.11.11
11/12/2024
Avada <= 7.11.6 – Unauthenticated Sensitive Information Exposure via Form Uploads Directory Listing
The Avada theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.11.6 via the '/wp-content/uploads/fusion-forms/' directory. This makes it possible for unauthenticated attackers to extract sensitive data uploaded via an Avada…
*-7.11.6
7.11.7
20/03/2024
Avada <= 7.11.6 – Authenticated (Contributor+) Server-Side Request Forgery via form_to_url_action
The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.11.6 via the form_to_url_action function. This makes it possible for authenticated attackers, with…
*-7.11.6
7.11.7
20/03/2024
Avada <= 7.11.6 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The Avada theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 7.11.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it…
*-7.11.6
7.11.7
20/03/2024
Avada <= 7.11.6 – Authenticated (Admin+) SQL Injection via entry
The Avada theme for WordPress is vulnerable to SQL Injection via the 'entry' parameter in all versions up to, and including, 7.11.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the…
*-7.11.6
7.11.7
20/03/2024
Avada <= 7.11.5 – Authenticated(Contributor+) Sensitive Information Exposure via Form Entries
The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Sensitive Information Exposure in versions up to and including 7.11.5 via the form entries page. This makes it possible for authenticated attackers, with…
*-7.11.5
7.11.6
01/03/2024
Avada | Website Builder For WordPress & WooCommerce <= 7.11.4 – Authenticated (Contributor+) Arbitrary File Upload
The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajax_import_options() function in all versions up to, and including, 7.11.4. This makes…
*-7.11.4
7.11.5
28/02/2024
Avada <= 7.11.1 – Authenticated(Author+) Arbitrary File Upload via Zip Extraction
The Avada theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation when extracting zip files in the 'process_upload' and 'regenerate_icon_files' functions in versions up to, and including, 7.11.1. This makes it possible…
*-7.11.1
7.11.2
10/08/2023
Avada <= 7.11.1 – Missing Authorization
The Avada theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on an unknown function in versions up to, and including, 7.11.1. This makes it possible for authenticated attackers, with subscriber-level…
*-7.11.1
7.11.2
10/08/2023
Avada <= 7.11.1 – Authenticated(Contributor+) Arbitrary File Upload via 'ajax_import_options'
The Avada theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'ajax_import_options' function in versions up to, and including, 7.11.1. This makes it possible for authenticated attackers with contributor permissions…
*-7.11.1
7.11.2
10/08/2023
Avada <= 7.11.1 – Authenticated(Contributor+) Server Side Request Forgery via 'ajax_import_options'
The Avada theme for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 7.11.1 via the 'ajax_import_options' function. This can allow authenticated attackers with contributor privileges to make web requests to arbitrary locations originating…
*-7.11.1
7.11.2
10/08/2023
Avada <= 7.8.1 – Cross-Site Request Forgery
The Avada theme for WordPress is vulnerable to Cross-Site Request forgery in versions up to, and including, 7.8.1 in class-avada-admin.php. This allows unauthenticated attackers to perform actions on behalf of an administrator if they can trick that administrator…
*-7.8.1
7.8.2
21/09/2022
Fusion Builder <= 3.6.1 & Avada <= 7.6.1 – Unauthenticated Server-Side Request Forgery
The Fusion Builder plugin for WordPress, an Avada theme core plugin, is vulnerable to Server-Side Request Forgery in versions up to 3.6.2 along with the Avada theme in versions up to 7.6.2. This is due to insufficient validation…
[*, 7.6.2)
7.6.2
19/04/2022
Avada <= 7.4.1 – Stored Cross-Site Scripting
The Avada plugin for WordPress is vulnerable to Stored Cross-Site Scripting via improper escaping of HTML form entries in the backend in versions up to, and including, 7.4.1 due to insufficient input sanitization and output escaping. This makes…
*-7.4.1
7.4.2
10/09/2021
Avada <= 7.4.1 – Reflected Cross-Site Scripting
The Avada theme for WordPress is vulnerable to Reflected Cross-Site Scripting via improper escaping of bbPress searches in versions up to, and including, 7.4.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
*-7.4.1
7.4.2
10/09/2021
Thèmes également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.