Cross-Site Request Forgery in Avada Theme by ThemeFusion for WordPress
CVE-2017-18607
8.8HIGH
What is CVE-2017-18607?
The Avada theme, developed by ThemeFusion for WordPress, is vulnerable to Cross-Site Request Forgery (CSRF) prior to version 5.1.5. This vulnerability can allow attackers to exploit user sessions, potentially causing unauthorized actions on behalf of users without their consent.