Missing Authorization Vulnerability Affects Avada
CVE-2023-39312
8.8HIGH
What is CVE-2023-39312?
The vulnerability in ThemeFusion's Avada theme arises from a missing authorization check, leading to potential security risks such as unrestricted zip extraction. This flaw can be exploited in various versions of Avada, posing a significant threat to WordPress sites that utilize this popular theme. It is crucial for users to apply updates and implement security measures to safeguard their websites against exploitation.
Affected Version(s)
Avada <= 7.11.1