Impact
The Avada WordPress theme contains a reflected XSS flaw in the lang query parameter. Unauthenticated attackers can insert arbitrary JavaScript into the href attribute of a link that a user visits. If a user follows a malicious link, the script runs in the victim’s browser, potentially compromising session cookies, defacing the site, or executing further attacks that rely on the victim’s authenticated session. The weakness is a classic input‑validation flaw in which user data is concatenated into output without proper escaping.
Affected Systems
All WordPress installations that use the ThemeFusion Avada theme version 7.16.1 or earlier are affected. The issue manifests in any site that supports the multilingual functionality of Avada, typically WordPress sites that include WooCommerce.
Risk and Exploitability
The CVSS score of 6.1 indicates a moderate severity. Because the flaw is exploitable via a simple URL injection, any user who clicks a crafted link can trigger the payload. EPSS values are not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no widespread exploitation reports yet. Nevertheless, since a reflected XSS is a basic vector for cookie theft and session hijacking, the risk remains significant for sites that permit untrusted traffic.
OpenCVE Enrichment