Description
The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Stored Cross-Site Scripting via the user profile 'Author Page' social link contact-method fields (author_facebook, author_twitter, author_linkedin, author_dribble, author_whatsapp, author_email) in versions up to, and including, 7.16.1. Avada registers these fields through the user_contactmethods filter and, on the author archive, emits them inside an anchor href using only esc_attr() in Fusion_Social_Icon::get_markup(), which escapes HTML metacharacters but does not reject dangerous URL schemes such as javascript:. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses their author page and clicks the injected social icon (a click is required, and the site must have 'Open Social Icons in a New Window' set to Off so the browser doesn't block the javascript: URL from opening in a new tab).
Published: 2026-10-10
Score: 6.4 Medium
EPSS: n/a
KEV: No
Impact: Stored Cross‑Site Scripting (XSS) enabling arbitrary client‑side script execution
Action: Patch Immediately
AI Analysis

Impact

The vulnerability resides in the Avada WordPress theme, where social link fields in the user profile are rendered into anchor elements without rejecting dangerous URL schemes. An authenticated user with Subscriber-level privileges can supply a javascript: URL in fields such as author_facebook, author_twitter, etc. When a visitor accesses the author page and clicks the icon, the browser executes the injected script, which can result in credential theft, website defacement, or phishing. This is a classic Stored XSS flaw identified as CWE‑79.

Affected Systems

Avada | Website Builder For WordPress & WooCommerce theme version 7.16.1 and all earlier releases by ThemeFusion that are installed on WordPress sites using this theme.

Risk and Exploitability

The CVSS score of 6.4 indicates moderate severity. The EPSS score is not available, so the current exploitation probability is unknown. The vulnerability is not listed in CISA's KEV catalog. Attackers need write access to a subscriber or higher account and the site configuration 'Open Social Icons in a New Window' must be Off so the javascript: URL is executed in the same tab. The exploit requires a victim to click the malicious icon, making it non‑automatic but still feasible under these conditions.

Generated by OpenCVE AI on October 10, 2026 at 09:35 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Avada theme to version 7.16.2 or later, which removes the vulnerable rendering code.
  • Change the WordPress administrative setting for social icons to open in a new window, ensuring that javascript: URLs are blocked from execution in the same tab.
  • For existing profiles that contain malicious URLs, sanitize or delete the social link fields via the admin interface or a sanitizing plugin before the data is rendered.

Generated by OpenCVE AI on October 10, 2026 at 09:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 08:00:00 +0000

Type Values Removed Values Added
Description The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Stored Cross-Site Scripting via the user profile 'Author Page' social link contact-method fields (author_facebook, author_twitter, author_linkedin, author_dribble, author_whatsapp, author_email) in versions up to, and including, 7.16.1. Avada registers these fields through the user_contactmethods filter and, on the author archive, emits them inside an anchor href using only esc_attr() in Fusion_Social_Icon::get_markup(), which escapes HTML metacharacters but does not reject dangerous URL schemes such as javascript:. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses their author page and clicks the injected social icon (a click is required, and the site must have 'Open Social Icons in a New Window' set to Off so the browser doesn't block the javascript: URL from opening in a new tab).
Title Avada | Website Builder For WordPress & WooCommerce <= 7.16.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'author_facebook' User Profile Field
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-10T07:41:48.155Z

Reserved: 2026-09-24T12:23:53.982Z

Link: CVE-2026-97340

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T08:17:08.307

Modified: 2026-10-10T08:17:08.307

Link: CVE-2026-97340

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T09:45:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')