Missing Authorization Vulnerability Affects Avada
CVE-2023-39312
8.8HIGH
Summary
The vulnerability in ThemeFusion's Avada theme arises from a missing authorization check, leading to potential security risks such as unrestricted zip extraction. This flaw can be exploited in various versions of Avada, posing a significant threat to WordPress sites that utilize this popular theme. It is crucial for users to apply updates and implement security measures to safeguard their websites against exploitation.
Affected Version(s)
Avada <= 7.11.1
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Rafie Muhammad (Patchstack)