Stored Cross-Site Scripting in Avada WordPress Theme
CVE-2026-97340

6.4MEDIUM

What is CVE-2026-97340?

The Avada theme for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) attacks through the user profile 'Author Page' social link contact-method fields (e.g., author_facebook, author_twitter). This vulnerability allows authenticated attackers with Subscriber-level access and above to inject malicious scripts that execute when users visit an author's page and interact with the compromised social icons. Despite employing the esc_attr() function, the theme fails to adequately sanitize input for dangerous URL schemes such as 'javascript:', resulting in a significant risk for site users.

Affected Version(s)

Avada | Website Builder For WordPress & WooCommerce 0 <= 7.16.1

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Muhamad Visat
.