Sensitive Information Exposure in Avada Theme for WordPress
CVE-2024-2340
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 9 April 2024
What is CVE-2024-2340?
The Avada theme for WordPress contains a vulnerability that enables unauthenticated attackers to access sensitive information through the '/wp-content/uploads/fusion-forms/' directory. This flaw permits unauthorized extraction of files submitted via forms created using the Avada theme, potentially leading to data breaches and compromised privacy. All versions up to and including 7.11.6 are affected, highlighting the need for immediate updates and security measures to protect user data.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Avada | Website Builder For WordPress & WooCommerce * <= 7.11.6
References
EPSS Score
56% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved