Stored Cross-Site Scripting in Avada WordPress Theme
CVE-2026-97340
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 10 October 2026
What is CVE-2026-97340?
The Avada theme for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) attacks through the user profile 'Author Page' social link contact-method fields (e.g., author_facebook, author_twitter). This vulnerability allows authenticated attackers with Subscriber-level access and above to inject malicious scripts that execute when users visit an author's page and interact with the compromised social icons. Despite employing the esc_attr() function, the theme fails to adequately sanitize input for dangerous URL schemes such as 'javascript:', resulting in a significant risk for site users.
Affected Version(s)
Avada | Website Builder For WordPress & WooCommerce 0 <= 7.16.1