Theme Fusion develops Avada, a widely adopted WordPress page-builder and theme platform that serves as a foundational component across many WordPress installations. The vendor's vulnerability disclosures, while modest in volume, reflect the complexity of integrating deeply with WordPress and handling user-generated content and administrative inputs. Defenders should treat updates to this product as broadly applicable given its distribution across the WordPress ecosystem; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Theme Fusion over time
Signals from CVEs in this vendor scope (23 CVEs).
23 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-1386CRITICAL The Fusion Builder WordPress plugin before 3.6.2, used in the Avada theme, does not validate a parameter in its forms which could be used to initiate arbitrary HTTP requests. The d | May 16, 2022 | 9.8 | 76 | NO | YES |
CVE-2024-2340MEDIUM The Avada theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.11.6 via the '/wp-content/uploads/fusion-forms/' directory. Th | Apr 9, 2024 | 5.3 | 38 | NO | YES |
CVE-2024-13346CRITICAL The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 7.11.13. This is du | Feb 13, 2025 | 9.8 | 29 | NO | NO |
CVE-2022-41996HIGH Cross-Site Request Forgery (CSRF) vulnerability in ThemeFusion Avada premium theme versions <= 7.8.1 on WordPress leading to arbitrary plugin installation/activation. | Oct 27, 2022 | 8.8 | 28 | NO | NO |
CVE-2025-64634HIGH Missing Authorization vulnerability in ThemeFusion Avada avada allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Avada: from n/a through <= 7.13.2. | Dec 16, 2025 | 8.8 | 27 | NO | NO |
CVE-2024-13345CRITICAL The Avada Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.11.13. This is due to the software allowing users to e | Feb 13, 2025 | 9.8 | 27 | NO | NO |
CVE-2017-18607HIGH The avada theme before 5.1.5 for WordPress has CSRF. | Sep 10, 2019 | 8.8 | 27 | NO | NO |
CVE-2023-39312HIGH Missing Authorization vulnerability in ThemeFusion Avada.This issue affects Avada: from n/a through 7.11.1. | Jun 19, 2024 | 8.8 | 26 | NO | NO |
CVE-2023-39307HIGH Unrestricted Upload of File with Dangerous Type vulnerability in ThemeFusion Avada.This issue affects Avada: from n/a through 7.11.1. | Mar 26, 2024 | 8.8 | 24 | NO | NO |
CVE-2023-39922HIGH Missing Authorization vulnerability in ThemeFusion Avada.This issue affects Avada: from n/a through 7.11.1. | Jun 19, 2024 | 8.8 | 23 | NO | NO |
Signals from CVEs in this vendor scope (23 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Theme Fusion.
Media articles that mention a CVE ID that affects a product developed by Theme Fusion — matched by CVE ID, not by vendor name.