Avada | Website Builder For WordPress & WooCommerce

Explore Avada | Website Builder For WordPress & WooCommerce vulnerabilities across all versions. Currently tracking 23 known vulnerabilities, including severity, impact, and patch status.

01234567891026.04.2017Today26.04.20178.8Avada <= 5.1.4 - Cross-Site Request Forgery CVSS 8.8 · 26.04.20176.1Avada <= 5.1.4 - Stored Cross-Site Scripting CVSS 6.1 · 26.04.201724.04.20206.4Avada <= 6.2.2 - Authenticated (Contributor+) Cross-Site Scripting CVSS 6.4 · 24.04.202010.09.20216.4Avada <= 7.4.1 - Stored Cross-Site Scripting CVSS 6.4 · 10.09.20216.1Avada <= 7.4.1 - Reflected Cross-Site Scripting CVSS 6.1 · 10.09.202119.04.20228.3Fusion Builder <= 3.6.1 & Avada <= 7.6.1 - Unauthenticated Server-Side Request Forgery CVSS 8.3 · 19.04.202221.09.20228.8Avada <= 7.8.1 - Cross-Site Request Forgery CVSS 8.8 · 21.09.202210.08.20237.5Avada <= 7.11.1 - Authenticated(Contributor+) Arbitrary File Upload via 'ajax_import_options' CVSS 7.5 · 10.08.20234.3Avada <= 7.11.1 - Missing Authorization CVSS 4.3 · 10.08.20238.8Avada <= 7.11.1 - Authenticated(Author+) Arbitrary File Upload via Zip Extraction CVSS 8.8 · 10.08.20238.5Avada <= 7.11.1 - Authenticated(Contributor+) Server Side Request Forgery via 'ajax_import_options' CVSS 8.5 · 10.08.202328.02.20248.8Avada | Website Builder For WordPress & WooCommerce <= 7.11.4 - Authenticated (Contributor+) Arbitrary File Upload CVSS 8.8 · 28.02.202401.03.20246.5Avada <= 7.11.5 - Authenticated(Contributor+) Sensitive Information Exposure via Form Entries CVSS 6.5 · 01.03.202420.03.20246.4Avada <= 7.11.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode CVSS 6.4 · 20.03.20247.2Avada <= 7.11.6 - Authenticated (Admin+) SQL Injection via entry CVSS 7.2 · 20.03.20245.3Avada <= 7.11.6 - Unauthenticated Sensitive Information Exposure via Form Uploads Directory Listing CVSS 5.3 · 20.03.20246.4Avada <= 7.11.6 - Authenticated (Contributor+) Server-Side Request Forgery via form_to_url_action CVSS 6.4 · 20.03.202411.12.20244.3Avada <= 7.11.10 - Cross-Site Request Forgery CVSS 4.3 · 11.12.202424.01.20255.3Avada <= 7.11.10 - Missing Authorization CVSS 5.3 · 24.01.202512.02.20257.3Avada Theme <= 7.11.13 - Unauthenticated Arbitrary Shortcode Execution CVSS 7.3 · 12.02.202503.10.20254.3Avada <= 7.13.2 - Missing Authorization CVSS 4.3 · 03.10.202522.04.20264.3Avada < 7.13.2 - Cross-Site Request Forgery CVSS 4.3 · 22.04.202615.06.20267.5Avada <= 3.15.3 - Authenticated (Contributor+) PHP Object Injection CVSS 7.5 · 15.06.2026

Strategic Overview

Avg CVSSMedium
6.7/ 10
Patch Coverage100%
Open

0

Fixed

23

Get automatic notifications for all Avada | Website Builder For WordPress & WooCommerce vulnerabilities before they are exploited.

Vulnerability Records

23 records
Showing 1–10 of 23 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C