Record summary

CVE-2024-2340 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.

Description

The Avada theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.11.6 via the '/wp-content/uploads/fusion-forms/' directory. This makes it possible for unauthenticated attackers to extract sensitive data uploaded via an Avada created form with a file upload mechanism.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 8, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Avada | Website Builder For WordPress & WooCommerce

Browse ThemeFusion / Avada | Website Builder For WordPress & WooCommerce

Default status: unaffected

CVE ListThrough 7.11.6affected

Default status: unknown

CVE ListBefore 7.11.7affected

Nuclei templates

1
ProjectDiscoveryMEDIUMAvada < 7.11.7 - Information DisclosureCVSS 5.3

The Avada theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.11.6 via the '/wp-content/uploads/fusion-forms/' directory. This makes it possible for unauthenticated attackers to extract sensitive data uploaded via an Avada created form with a file upload mechanism.

Impact

Unauthenticated attackers can access sensitive files uploaded via Avada forms by browsing the fusion-forms directory, potentially exposing personal information or confidential data.

Remediation

Update Avada theme to version 7.11.7 or later.

Authorst3l3machus
Template tagscvecve2024wp-themewpwordpresswpscanavadaexposurevuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Source: ProjectDiscovery

References

3