theme

Avada Vulnerabilities

52 known security issues reported for the Avada WordPress theme. Most recent disclosed Aug 25, 2026.

1 critical 10 high 13 medium

Running Avada on your site? Check whether your installed version is affected.

Scan your site free

Avada <= 7.16 and Fusion Builder <= 3.16 - Unauthenticated Remote Code Execution via Arbitrary File Write

critical

The Avada theme for WordPress is vulnerable to Arbitrary File Write in all versions up to, and including, 7.16 when the Fusion Builder plugin is installed and active in versions up to, and including, 3.16. This is due to a chain of authorization and input validation weaknesses across the two components that makes it po...

CVSS:
9.8
Affected:
up to 7.16
Fixed in:
7.16.1
Disclosed:
Aug 25, 2026

CVE-2026-18431 on NVD →

Avada <= 3.15.3 - Authenticated (Contributor+) PHP Object Injection

high

The Avada theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.15.3 via deserialization of untrusted input. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable softwa...

CVSS:
7.5
Affected:
up to 3.15.3
Fixed in:
3.15.4
Disclosed:
Jun 15, 2026

CVE-2026-12256 on NVD →

Avada < 7.13.2 - Cross-Site Request Forgery

medium

The Avada theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 7.13.2. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can trick a site administrator...

CVSS:
4.3
Affected:
up to 7.13.2
Fixed in:
7.13.2
Disclosed:
Apr 22, 2026

CVE-2025-58922 on NVD →

Avada <= 7.13.2 - Missing Authorization

medium

The Avada theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 7.13.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 7.13.2
Fixed in:
7.13.3
Disclosed:
Oct 3, 2025

CVE-2025-64634 on NVD →

Avada [Avada] < 7.11.11

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup All In One Slider Responsive allows SQL Injection. This issue affects All In One Slider Responsive: from n/a through 3.7.9.

Affected:
up to 7.11.11
Fixed in:
7.11.11
Disclosed:
Jul 4, 2025

CVE-2025-24748 on NVD →

Avada [Avada] < 7.11.14

unknown

[en] The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 7.11.13. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes i...

Affected:
up to 7.11.14
Fixed in:
7.11.14
Disclosed:
Feb 13, 2025

CVE-2024-13346 on NVD →

Avada Theme <= 7.11.13 - Unauthenticated Arbitrary Shortcode Execution

high

The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 7.11.13. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it pos...

CVSS:
7.3
Affected:
up to 7.11.13
Fixed in:
7.11.14
Disclosed:
Feb 12, 2025

CVE-2024-13346 on NVD →

Avada <= 7.11.10 - Missing Authorization

medium

The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 7.11.10. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 7.11.10
Fixed in:
7.11.11
Disclosed:
Jan 24, 2025

CVE-2025-24748 on NVD →

Avada [Avada] < 7.11.11

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in ThemeFusion Avada.This issue affects Avada: from n/a through 7.11.10.

Affected:
up to 7.11.11
Fixed in:
7.11.11
Disclosed:
Dec 16, 2024

CVE-2024-54357 on NVD →

Avada <= 7.11.10 - Cross-Site Request Forgery

medium

The Avada theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 7.11.10. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can trick a si...

CVSS:
4.3
Affected:
up to 7.11.10
Fixed in:
7.11.11
Disclosed:
Dec 11, 2024

CVE-2024-54357 on NVD →

Avada [Avada] < 7.11.2

unknown

[en] Missing Authorization vulnerability in ThemeFusion Avada.This issue affects Avada: from n/a through 7.11.1.

Affected:
up to 7.11.2
Fixed in:
7.11.2
Disclosed:
Jun 19, 2024

CVE-2023-39922 on NVD →

Avada [Avada] < 7.11.2

unknown

[en] Missing Authorization vulnerability in ThemeFusion Avada.This issue affects Avada: from n/a through 7.11.1.

Affected:
up to 7.11.2
Fixed in:
7.11.2
Disclosed:
Jun 19, 2024

CVE-2023-39312 on NVD →

Avada [Avada] < 7.11.7

unknown

[en] The Avada theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 7.11.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and a...

Affected:
up to 7.11.7
Fixed in:
7.11.7
Disclosed:
Apr 9, 2024

CVE-2024-2311 on NVD →

Avada [Avada] < 7.11.7

unknown

[en] The Avada theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.11.6 via the '/wp-content/uploads/fusion-forms/' directory. This makes it possible for unauthenticated attackers to extract sensitive data uploaded via an Avada created form with a file upload mech...

Affected:
up to 7.11.7
Fixed in:
7.11.7
Disclosed:
Apr 9, 2024

CVE-2024-2340 on NVD →

Avada [Avada] < 7.11.7

unknown

[en] The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.11.6 via the form_to_url_action function. This makes it possible for authenticated attackers, with contributor-level access and above, to make web request...

Affected:
up to 7.11.7
Fixed in:
7.11.7
Disclosed:
Apr 9, 2024

CVE-2024-2343 on NVD →

Avada [Avada] < 7.11.7

unknown

[en] The Avada theme for WordPress is vulnerable to SQL Injection via the 'entry' parameter in all versions up to, and including, 7.11.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticted attackers, with edit...

Affected:
up to 7.11.7
Fixed in:
7.11.7
Disclosed:
Apr 9, 2024

CVE-2024-2344 on NVD →

Avada [Avada] < 7.11.2

unknown

[en] Server-Side Request Forgery (SSRF) vulnerability in ThemeFusion Avada.This issue affects Avada: from n/a through 7.11.1.

Affected:
up to 7.11.2
Fixed in:
7.11.2
Disclosed:
Mar 28, 2024

CVE-2023-39313 on NVD →

Avada [Avada] < 7.11.2

unknown

[en] Unrestricted Upload of File with Dangerous Type vulnerability in ThemeFusion Avada.This issue affects Avada: from n/a through 7.11.1.

Affected:
up to 7.11.2
Fixed in:
7.11.2
Disclosed:
Mar 26, 2024

CVE-2023-39307 on NVD →

Avada <= 7.11.6 - Authenticated (Admin+) SQL Injection via entry

high

The Avada theme for WordPress is vulnerable to SQL Injection via the 'entry' parameter in all versions up to, and including, 7.11.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticted attackers, with editor-le...

CVSS:
7.2
Affected:
up to 7.11.6
Fixed in:
7.11.7
Disclosed:
Mar 20, 2024

CVE-2024-2344 on NVD →

Avada <= 7.11.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The Avada theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 7.11.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above...

CVSS:
6.4
Affected:
up to 7.11.6
Fixed in:
7.11.7
Disclosed:
Mar 20, 2024

CVE-2024-2311 on NVD →

Avada <= 7.11.6 - Authenticated (Contributor+) Server-Side Request Forgery via form_to_url_action

medium

The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.11.6 via the form_to_url_action function. This makes it possible for authenticated attackers, with contributor-level access and above, to make web requests to...

CVSS:
6.4
Affected:
up to 7.11.6
Fixed in:
7.11.7
Disclosed:
Mar 20, 2024

CVE-2024-2343 on NVD →

Avada <= 7.11.6 - Unauthenticated Sensitive Information Exposure via Form Uploads Directory Listing

medium

The Avada theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.11.6 via the '/wp-content/uploads/fusion-forms/' directory. This makes it possible for unauthenticated attackers to extract sensitive data uploaded via an Avada created form with a file upload mechanism...

CVSS:
5.3
Affected:
up to 7.11.6
Fixed in:
7.11.7
Disclosed:
Mar 20, 2024

CVE-2024-2340 on NVD →

Avada [Avada] < 7.11.6

unknown

[en] The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Sensitive Information Exposure in versions up to and including 7.11.5 via the form entries page. This makes it possible for authenticated attackers, with contributor access and above, to view the contents of all form submi...

Affected:
up to 7.11.6
Fixed in:
7.11.6
Disclosed:
Mar 13, 2024

CVE-2024-1668 on NVD →

Avada <= 7.11.5 - Authenticated(Contributor+) Sensitive Information Exposure via Form Entries

medium

The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Sensitive Information Exposure in versions up to and including 7.11.5 via the form entries page. This makes it possible for authenticated attackers, with contributor access and above, to view the contents of all form submission...

CVSS:
6.5
Affected:
up to 7.11.5
Fixed in:
7.11.6
Disclosed:
Mar 1, 2024

CVE-2024-1668 on NVD →

Avada [Avada] < 7.11.5

unknown

[en] The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajax_import_options() function in all versions up to, and including, 7.11.4. This makes it possible for authenticated attackers, with contributor-level acce...

Affected:
up to 7.11.5
Fixed in:
7.11.5
Disclosed:
Feb 29, 2024

CVE-2024-1468 on NVD →

Avada | Website Builder For WordPress & WooCommerce <= 7.11.4 - Authenticated (Contributor+) Arbitrary File Upload

high

The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajax_import_options() function in all versions up to, and including, 7.11.4. This makes it possible for authenticated attackers, with contributor-level access an...

CVSS:
8.8
Affected:
up to 7.11.4
Fixed in:
7.11.5
Disclosed:
Feb 28, 2024

CVE-2024-1468 on NVD →

Avada <= 7.11.1 - Authenticated(Author+) Arbitrary File Upload via Zip Extraction

high

The Avada theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation when extracting zip files in the 'process_upload' and 'regenerate_icon_files' functions in versions up to, and including, 7.11.1. This makes it possible for authenticated attackers with author permissions to upload...

CVSS:
8.8
Affected:
up to 7.11.1
Fixed in:
7.11.2
Disclosed:
Aug 10, 2023

CVE-2023-39312 on NVD →

Avada <= 7.11.1 - Authenticated(Contributor+) Server Side Request Forgery via 'ajax_import_options'

high

The Avada theme for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 7.11.1 via the 'ajax_import_options' function. This can allow authenticated attackers with contributor privileges to make web requests to arbitrary locations originating from the web application and can be used...

CVSS:
8.5
Affected:
up to 7.11.1
Fixed in:
7.11.2
Disclosed:
Aug 10, 2023

CVE-2023-39313 on NVD →

Avada <= 7.11.1 - Authenticated(Contributor+) Arbitrary File Upload via 'ajax_import_options'

high

The Avada theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'ajax_import_options' function in versions up to, and including, 7.11.1. This makes it possible for authenticated attackers with contributor permissions to upload arbitrary files on the affected site's serve...

CVSS:
7.5
Affected:
up to 7.11.1
Fixed in:
7.11.2
Disclosed:
Aug 10, 2023

CVE-2023-39307 on NVD →

Avada <= 7.11.1 - Missing Authorization

medium

The Avada theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on an unknown function in versions up to, and including, 7.11.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to save Portfolio permalinks.

CVSS:
4.3
Affected:
up to 7.11.1
Fixed in:
7.11.2
Disclosed:
Aug 10, 2023

CVE-2023-39922 on NVD →

Avada [Avada] < 6.2.3

unknown

[en] The Avada theme for WordPress is vulnerable to Stored Cross-Site Scripting via the update_layout function in versions up to, and including, 6.2.3 due to insufficient input sanitization and output escaping. This makes it possible for contributor-level attackers, and above, to inject arbitrary web scripts in pages t...

Affected:
up to 6.2.3
Fixed in:
6.2.3
Disclosed:
Jun 7, 2023

CVE-2020-36711 on NVD →

Avada [Avada] < 7.8.2

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in ThemeFusion Avada premium theme versions <= 7.8.1 on WordPress leading to arbitrary plugin installation/activation.

Affected:
up to 7.8.2
Fixed in:
7.8.2
Disclosed:
Oct 27, 2022

CVE-2022-41996 on NVD →

Avada <= 7.8.1 - Cross-Site Request Forgery

high

The Avada theme for WordPress is vulnerable to Cross-Site Request forgery in versions up to, and including, 7.8.1 in class-avada-admin.php. This allows unauthenticated attackers to perform actions on behalf of an administrator if they can trick that administrator into performing an action, such as clicking a link.

CVSS:
8.8
Affected:
up to 7.8.1
Fixed in:
7.8.2
Disclosed:
Sep 21, 2022

CVE-2022-41996 on NVD →

Avada [Avada] < 7.6.2

unknown

[en] The Fusion Builder WordPress plugin before 3.6.2, used in the Avada theme, does not validate a parameter in its forms which could be used to initiate arbitrary HTTP requests. The data returned is then reflected back in the application's response. This could be used to interact with hosts on the server's local netw...

Affected:
up to 7.6.2
Fixed in:
7.6.2
Disclosed:
May 16, 2022

CVE-2022-1386 on NVD →

Fusion Builder <= 3.6.1 & Avada <= 7.6.1 - Unauthenticated Server-Side Request Forgery

high

The Fusion Builder plugin for WordPress, an Avada theme core plugin, is vulnerable to Server-Side Request Forgery in versions up to 3.6.2 along with the Avada theme in versions up to 7.6.2. This is due to insufficient validation in one of its form parameters. This makes it possible for unauthenticated attackers to inte...

CVSS:
8.3
Affected:
up to 7.6.2
Fixed in:
7.6.2
Disclosed:
Apr 19, 2022

CVE-2022-1386 on NVD →

Avada <= 7.4.1 - Stored Cross-Site Scripting

medium

The Avada plugin for WordPress is vulnerable to Stored Cross-Site Scripting via improper escaping of HTML form entries in the backend in versions up to, and including, 7.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in...

CVSS:
6.4
Affected:
up to 7.4.1
Fixed in:
7.4.2
Disclosed:
Sep 10, 2021

Avada <= 7.4.1 - Reflected Cross-Site Scripting

medium

The Avada theme for WordPress is vulnerable to Reflected Cross-Site Scripting via improper escaping of bbPress searches in versions up to, and including, 7.4.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that e...

CVSS:
6.1
Affected:
up to 7.4.1
Fixed in:
7.4.2
Disclosed:
Sep 10, 2021

Avada [Avada] < 7.4.2

unknown

The Avada plugin for WordPress is vulnerable to Stored Cross-Site Scripting via improper escaping of HTML form entries in the backend in versions up to, and including, 7.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in...

Affected:
up to 7.4.2
Fixed in:
7.4.2
Disclosed:
Sep 10, 2021

Avada [Avada] < 7.4.2

unknown

The Avada theme for WordPress is vulnerable to Reflected Cross-Site Scripting via improper escaping of bbPress searches in versions up to, and including, 7.4.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that e...

Affected:
up to 7.4.2
Fixed in:
7.4.2
Disclosed:
Sep 10, 2021

Avada [Avada] < 6.2.3

unknown

Stored Cross-Site Scripting (XSS) vulnerability discovered by NinTechNet in WordPress Avada premium theme (versions <= 6.2.2).

Affected:
up to 6.2.3
Fixed in:
6.2.3
Disclosed:
May 1, 2020

Avada [Avada] < 6.2.3

unknown

Arbitrary Post Creation, Edition, and Deletion vulnerability discovered by NinTechNet in WordPress Avada premium theme (versions <= 6.2.2).

Affected:
up to 6.2.3
Fixed in:
6.2.3
Disclosed:
May 1, 2020

Avada <= 6.2.2 - Authenticated (Contributor+) Cross-Site Scripting

medium

The Avada theme for WordPress is vulnerable to Stored Cross-Site Scripting via the update_layout function in versions up to, and including, 6.2.3 due to insufficient input sanitization and output escaping. This makes it possible for contributor-level attackers, and above, to inject arbitrary web scripts in pages that w...

CVSS:
6.4
Affected:
up to 6.2.3
Fixed in:
6.2.3
Disclosed:
Apr 24, 2020

CVE-2020-36711 on NVD →

Avada [Avada] < 5.1.5

unknown

[en] The avada theme before 5.1.5 for WordPress has stored XSS.

Affected:
up to 5.1.5
Fixed in:
5.1.5
Disclosed:
Sep 10, 2019

CVE-2017-18606 on NVD →

Avada [Avada] < 5.1.5

unknown

[en] The avada theme before 5.1.5 for WordPress has CSRF.

Affected:
up to 5.1.5
Fixed in:
5.1.5
Disclosed:
Sep 10, 2019

CVE-2017-18607 on NVD →

Avada <= 5.1.4 - Cross-Site Request Forgery

high

The Avada theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.4. This is due to missing nonce validation on the fusion_builder_importer() function. This makes it possible for unauthenticated attackers to trigger the importer and upload arbitrary files via a forged reque...

CVSS:
8.8
Affected:
up to 5.1.5
Fixed in:
5.1.5
Disclosed:
Apr 26, 2017

CVE-2017-18607 on NVD →

Avada <= 5.1.4 - Stored Cross-Site Scripting

medium

The Avada theme for WordPress is vulnerable to Stored Cross-Site Scripting via avada_portfolio_category_slug parameter saved by the save_permalink_settings() function called via 'admin_init' in versions up to 5.1.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated atta...

CVSS:
6.1
Affected:
up to 5.1.5
Fixed in:
5.1.5
Disclosed:
Apr 26, 2017

CVE-2017-18606 on NVD →

Avada [Avada] < 3.4

unknown

[en] The ThemePunch Slider Revolution (revslider) plugin before 3.0.96 for WordPress and Showbiz Pro plugin 1.7.1 and earlier for Wordpress does not properly restrict access to administrator AJAX functionality, which allows remote attackers to (1) upload and execute arbitrary files via an update_plugin action; (2) dele...

Affected:
up to 3.4
Fixed in:
3.4
Disclosed:
Jun 30, 2015

CVE-2014-9735 on NVD →

Avada [Avada] < 3.4 (unfixed)

unknown

[en] Directory traversal vulnerability in the Elegant Themes Divi theme for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the img parameter in a revslider_show_image action to wp-admin/admin-ajax.php. NOTE: this vulnerability may be a duplicate of CVE-2014-9734.

Affected:
up to 3.4
Fix:
No patched version reported
Disclosed:
Feb 11, 2015

CVE-2015-1579 on NVD →

Avada [Avada] < 7.4.2

unknown

The Avada Forms component allowed unescaped HTML form entries to be loaded on the backend.

Affected:
up to 7.4.2
Fixed in:
7.4.2

Avada [Avada] < 7.4.2

unknown

The theme does not properly escape bbPress searches before outputting them back as breadcrumbs, leading to a Reflected Cross-Site Scripting issue.

Affected:
up to 7.4.2
Fixed in:
7.4.2

Avada [Avada] < 6.2.3

unknown

The Avada theme for WordPress is vulnerable to Stored Cross-Site Scripting via the update_layout function in versions up to, and including, 6.2.3 due to insufficient input sanitization and output escaping. This makes it possible for contributor level attackers to inject arbitrary web scripts in pages that will execute...

Affected:
up to 6.2.3
Fixed in:
6.2.3

Avada [Avada] <= 7.11.5 (unfixed)

unknown

Update the WordPress Avada theme to the latest available version (at least 7.11.6). Muhammad Zeeshan (Xib3rR4dAr) discovered and reported this Sensitive Data Exposure vulnerability in WordPress Avada Theme. This vulnerability has been fixed in version 7.11.6. Have additional information or questions about this entry?...

Affected:
up to 7.11.5
Fix:
No patched version reported

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database