Avada
Vendor:
First CVE: Sep 10, 2019 · Active for 6 years
19
Total CVEs
More Total CVEs than 93% of tracked products
3.8
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 49% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Avada over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 10, 2019
6 years ago
Most Recent CVE
Dec 16, 2025
222 days ago
CVE Severity & Scoring
Avada19 CVEs
42%
47%
11%
All CVEs352,708 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network19 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low19 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None12 (63.2%)
Unknown0 (0.0%)
Required7 (36.8%)
Privileges Required
Low11 (57.9%)
High1 (5.3%)
None7 (36.8%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-1386CRITICAL The Fusion Builder WordPress plugin before 3.6.2, used in the Avada theme, does not validate a parameter in its forms which could be used to initiate arbitrary HTTP requests. The d | May 16, 2022 | 9.8 | 76 | NO | YES |
CVE-2024-2340MEDIUM The Avada theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.11.6 via the '/wp-content/uploads/fusion-forms/' directory. Th | Apr 9, 2024 | 5.3 | 38 | NO | YES |
CVE-2024-13346CRITICAL The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 7.11.13. This is du | Feb 13, 2025 | 9.8 | 29 | NO | NO |
CVE-2022-41996HIGH Cross-Site Request Forgery (CSRF) vulnerability in ThemeFusion Avada premium theme versions <= 7.8.1 on WordPress leading to arbitrary plugin installation/activation. | Oct 27, 2022 | 8.8 | 28 | NO | NO |
CVE-2025-64634HIGH Missing Authorization vulnerability in ThemeFusion Avada avada allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Avada: from n/a through <= 7.13.2. | Dec 16, 2025 | 8.8 | 27 | NO | NO |
CVE-2017-18607HIGH The avada theme before 5.1.5 for WordPress has CSRF. | Sep 10, 2019 | 8.8 | 27 | NO | NO |
CVE-2023-39312HIGH Missing Authorization vulnerability in ThemeFusion Avada.This issue affects Avada: from n/a through 7.11.1. | Jun 19, 2024 | 8.8 | 26 | NO | NO |
CVE-2023-39307HIGH Unrestricted Upload of File with Dangerous Type vulnerability in ThemeFusion Avada.This issue affects Avada: from n/a through 7.11.1. | Mar 26, 2024 | 8.8 | 24 | NO | NO |
CVE-2023-39922HIGH Missing Authorization vulnerability in ThemeFusion Avada.This issue affects Avada: from n/a through 7.11.1. | Jun 19, 2024 | 8.8 | 23 | NO | NO |
CVE-2024-1468HIGH The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajax_import_options() | Feb 29, 2024 | 8.8 | 22 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (19 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
10.5% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (19 CVEs).
Media Mentions
Signals from CVEs in this product scope (19 CVEs).
Top CNAs Publishing CVEs For Avada
Top CWEs
Versions
No cataloged versions.