VendorsTheme-fusionavadaall versions
Vulnerabilities

Theme-fusion Avada

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

19CVEs
CVE-2022-1386
Fusion Builder < 3.6.2 - Unauthenticated SSRF
Published 2022-05-16 · Modified
9.8EPSS 0.714
CVE-2024-13346
Avada Theme <= 7.11.13 - Unauthenticated Arbitrary Shortcode Execution
Published 2025-02-13 · Analyzed
9.8EPSS 0.023
CVE-2023-39312
WordPress Avada theme <= 7.11.1 - Auth. Unrestricted Zip Extraction vulnerability
Published 2024-06-19 · Modified
9.1EPSS 0.006
CVE-2024-1468
Avada | Website Builder For WordPress & WooCommerce <= 7.11.4 - Authenticated (Contributor+) Arbitrary File Upload
Published 2024-02-29 · Modified
8.8EPSS 0.012
CVE-2023-39307
WordPress Avada theme <= 7.11.1 - Authenticated Arbitrary File Upload vulnerability
Published 2024-03-26 · Modified
8.8EPSS 0.007
CVE-2017-18607
The avada theme before 5.1.5 for WordPress has CSRF.
Published 2019-09-10 · Modified
8.8EPSS 0.007
CVE-2022-41996
WordPress Avada premium theme <= 7.8.1 - Cross-Site Request Forgery (CSRF) vulnerability
Published 2022-10-27 · Modified
8.8EPSS 0.005
CVE-2023-39922
WordPress Avada theme <= 7.11.1 - Authenticated Broken Access Control vulnerability
Published 2024-06-19 · Analyzed
8.8EPSS 0.004
CVE-2023-39313
WordPress Avada theme <= 7.11.1 - Authenticated Server Side Request Forgery (SSRF) vulnerability
Published 2024-03-28 · Modified
7.7EPSS 0.006
CVE-2024-2344
Avada <= 7.11.6 - Authenticated (Admin+) SQL Injection via entry
Published 2024-04-09 · Modified
7.2EPSS 0.008
CVE-2024-1668
Avada <= 7.11.5 - Authenticated(Contributor+) Sensitive Information Exposure via Form Entries
Published 2024-03-13 · Modified
6.5EPSS 0.007
CVE-2024-2311
Avada <= 7.11.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Published 2024-04-09 · Modified
6.4EPSS 0.007
CVE-2020-36711
Avada <= 6.2.2 - Authenticated (Contributor+) Cross-Site Scripting
Published 2023-06-07 · Modified
6.4EPSS 0.006
CVE-2024-2343
Avada <= 7.11.6 - Authenticated (Contributor+) Server-Side Request Forgery via form_to_url_action
Published 2024-04-09 · Modified
6.4EPSS 0.005
CVE-2024-5628
Avada | Website Builder For WordPress & eCommerce <= 3.11.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via fusion_button Shortcode
Published 2024-09-13 · Analyzed
6.4EPSS 0.003
CVE-2017-18606
The avada theme before 5.1.5 for WordPress has stored XSS.
Published 2019-09-10 · Modified
6.1EPSS 0.009
CVE-2024-2340
Avada <= 7.11.6 - Unauthenticated Sensitive Information Exposure via Form Uploads Directory Listing
Published 2024-04-09 · Modified
5.3EPSS 0.280
CVE-2025-64634
WordPress Avada theme <= 7.13.2 - Broken Access Control vulnerability
Published 2025-12-16 · Modified
5.3EPSS 0.003
CVE-2024-54357
WordPress Avada theme <= 7.11.10 - Cross Site Request Forgery (CSRF) vulnerability
Published 2024-12-16 · Modified
4.3EPSS 0.002