Thème WordPress

Vulnérabilités Avada | Website Builder For WordPress & WooCommerce

Cette page rassemble les failles publiées pour Avada | Website Builder For WordPress & WooCommerce, leurs plages de versions affectées et les correctifs signalés dans la base locale.

23Vulnérabilités
0Critiques
23Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Avada | Website Builder For WordPress & WooCommerce

23 fiches

CVE-2026-12256 Élevée · 7,5
Avada | Website Builder For WordPress & WooCommerce

Avada <= 3.15.3 – Authenticated (Contributor+) PHP Object Injection

The Avada theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.15.3 via deserialization of untrusted input. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a…

Versions affectées

*-3.15.3

Correctif

3.15.4

Publication

15/06/2026

CVE-2024-2340 Moyenne · 5,3
Avada | Website Builder For WordPress & WooCommerce

Avada <= 7.11.6 – Unauthenticated Sensitive Information Exposure via Form Uploads Directory Listing

The Avada theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.11.6 via the '/wp-content/uploads/fusion-forms/' directory. This makes it possible for unauthenticated attackers to extract sensitive data uploaded via an Avada…

Versions affectées

*-7.11.6

Correctif

7.11.7

Publication

20/03/2024

CVE-2024-2343 Moyenne · 6,4
Avada | Website Builder For WordPress & WooCommerce

Avada <= 7.11.6 – Authenticated (Contributor+) Server-Side Request Forgery via form_to_url_action

The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.11.6 via the form_to_url_action function. This makes it possible for authenticated attackers, with…

Versions affectées

*-7.11.6

Correctif

7.11.7

Publication

20/03/2024

CVE-2024-2311 Moyenne · 6,4
Avada | Website Builder For WordPress & WooCommerce

Avada <= 7.11.6 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The Avada theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 7.11.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it…

Versions affectées

*-7.11.6

Correctif

7.11.7

Publication

20/03/2024

CVE-2024-1668 Moyenne · 6,5
Avada | Website Builder For WordPress & WooCommerce

Avada <= 7.11.5 – Authenticated(Contributor+) Sensitive Information Exposure via Form Entries

The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Sensitive Information Exposure in versions up to and including 7.11.5 via the form entries page. This makes it possible for authenticated attackers, with…

Versions affectées

*-7.11.5

Correctif

7.11.6

Publication

01/03/2024

CVE-2024-1468 Élevée · 8,8
Avada | Website Builder For WordPress & WooCommerce

Avada | Website Builder For WordPress & WooCommerce <= 7.11.4 – Authenticated (Contributor+) Arbitrary File Upload

The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajax_import_options() function in all versions up to, and including, 7.11.4. This makes…

Versions affectées

*-7.11.4

Correctif

7.11.5

Publication

28/02/2024

CVE-2023-39312 Élevée · 8,8
Avada | Website Builder For WordPress & WooCommerce

Avada <= 7.11.1 – Authenticated(Author+) Arbitrary File Upload via Zip Extraction

The Avada theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation when extracting zip files in the 'process_upload' and 'regenerate_icon_files' functions in versions up to, and including, 7.11.1. This makes it possible…

Versions affectées

*-7.11.1

Correctif

7.11.2

Publication

10/08/2023

CVE-2023-39307 Élevée · 7,5
Avada | Website Builder For WordPress & WooCommerce

Avada <= 7.11.1 – Authenticated(Contributor+) Arbitrary File Upload via 'ajax_import_options'

The Avada theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'ajax_import_options' function in versions up to, and including, 7.11.1. This makes it possible for authenticated attackers with contributor permissions…

Versions affectées

*-7.11.1

Correctif

7.11.2

Publication

10/08/2023

CVE-2023-39313 Élevée · 8,5
Avada | Website Builder For WordPress & WooCommerce

Avada <= 7.11.1 – Authenticated(Contributor+) Server Side Request Forgery via 'ajax_import_options'

The Avada theme for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 7.11.1 via the 'ajax_import_options' function. This can allow authenticated attackers with contributor privileges to make web requests to arbitrary locations originating…

Versions affectées

*-7.11.1

Correctif

7.11.2

Publication

10/08/2023

CVE-2022-1386 Élevée · 8,3
Avada | Website Builder For WordPress & WooCommerce

Fusion Builder <= 3.6.1 & Avada <= 7.6.1 – Unauthenticated Server-Side Request Forgery

The Fusion Builder plugin for WordPress, an Avada theme core plugin, is vulnerable to Server-Side Request Forgery in versions up to 3.6.2 along with the Avada theme in versions up to 7.6.2. This is due to insufficient validation…

Versions affectées

[*, 7.6.2)

Correctif

7.6.2

Publication

19/04/2022

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités