← Back to CVEs
CVE-2024-1668
MEDIUM6.5
Description
The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Sensitive Information Exposure in versions up to and including 7.11.5 via the form entries page. This makes it possible for authenticated attackers, with contributor access and above, to view the contents of all form submissions, including fields that are obfuscated (such as the contact form's "password" field).
CVE Details
CVSS v3.1 Score6.5
SeverityMEDIUM
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredLOW
User InteractionNONE
Published3/13/2024
Last Modified4/8/2026
Sourcenvd
Honeypot Sightings0
Affected Products
theme-fusion:avada
Weaknesses (CWE)
CWE-284
References
https://gist.github.com/Xib3rR4dAr/91bd37338022b15379f393356d1056a1(security@wordfence.com)
https://www.wordfence.com/threat-intel/vulnerabilities/id/cd224169-ae51-4af8-b6de-706ed580ff8d?source=cve(security@wordfence.com)
https://gist.github.com/Xib3rR4dAr/91bd37338022b15379f393356d1056a1(af854a3a-2127-422b-91ae-364da2661108)
https://www.wordfence.com/threat-intel/vulnerabilities/id/cd224169-ae51-4af8-b6de-706ed580ff8d?source=cve(af854a3a-2127-422b-91ae-364da2661108)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.