Impact
The vulnerability resides in the Avada WordPress theme, where social link fields in the user profile are rendered into anchor elements without rejecting dangerous URL schemes. An authenticated user with Subscriber-level privileges can supply a javascript: URL in fields such as author_facebook, author_twitter, etc. When a visitor accesses the author page and clicks the icon, the browser executes the injected script, which can result in credential theft, website defacement, or phishing. This is a classic Stored XSS flaw identified as CWE‑79.
Affected Systems
Avada | Website Builder For WordPress & WooCommerce theme version 7.16.1 and all earlier releases by ThemeFusion that are installed on WordPress sites using this theme.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity. The EPSS score is not available, so the current exploitation probability is unknown. The vulnerability is not listed in CISA's KEV catalog. Attackers need write access to a subscriber or higher account and the site configuration 'Open Social Icons in a New Window' must be Off so the javascript: URL is executed in the same tab. The exploit requires a victim to click the malicious icon, making it non‑automatic but still feasible under these conditions.
OpenCVE Enrichment