The Avada theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.11.6 via the '/wp-content/uploads/fusion-forms/' directory. This makes it possible for unauthenticated attackers to extract sensitive data uploaded via an Avada created form with a file upload mechanism.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 26 Feb 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:theme-fusion:avada:*:*:*:*:*:*:*:* | |
| Metrics |
ssvc
|
Fri, 31 Jan 2025 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Theme-fusion
Theme-fusion avada |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:theme-fusion:avada:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Theme-fusion
Theme-fusion avada |
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2024-08-08T18:27:14.000Z
Reserved: 2024-03-08T20:06:51.188Z
Link: CVE-2024-2340
Updated: 2024-08-01T19:11:53.384Z
Status : Analyzed
Published: 2024-04-09T19:15:32.520
Modified: 2025-01-31T01:57:32.613
Link: CVE-2024-2340
No data.
OpenCVE Enrichment
No data.
Weaknesses