PT-2024-18212 · WordPress · Avada

Muhammad Zeeshan

+1

·

Published

2024-03-13

·

Updated

2025-01-31

·

CVE-2024-1668

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Avada | Website Builder For WordPress & WooCommerce theme for WordPress versions up to and including 7.11.5
Description The issue allows authenticated attackers with contributor access and above to view the contents of all form submissions, including fields that are obfuscated, such as the contact form's password field, via the form entries page.
Recommendations For versions up to and including 7.11.5, update to a version later than 7.11.5 to resolve the issue. As a temporary workaround, consider restricting access to the form entries page to minimize the risk of exploitation.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2024-1668

Affected Products

Avada