Description
The Avada theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.11.6 via the '/wp-content/uploads/fusion-forms/' directory. This makes it possible for unauthenticated attackers to extract sensitive data uploaded via an Avada created form with a file upload mechanism.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Wed, 08 Apr 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Avada <= 7.11.6 - Unauthenticated Sensitive Information Exposure via Form Uploads Directory Listing | |
| Weaknesses | CWE-548 |
Thu, 26 Feb 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:theme-fusion:avada:*:*:*:*:*:*:*:* | |
| Metrics |
ssvc
|
Fri, 31 Jan 2025 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Theme-fusion
Theme-fusion avada |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:theme-fusion:avada:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Theme-fusion
Theme-fusion avada |
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:06:13.768Z
Reserved: 2024-03-08T20:06:51.188Z
Link: CVE-2024-2340
Updated: 2024-08-01T19:11:53.384Z
Status : Modified
Published: 2024-04-09T19:15:32.520
Modified: 2026-04-08T18:21:04.283
Link: CVE-2024-2340
No data.
OpenCVE Enrichment
No data.
Weaknesses