Avada
AvadaVulnerabilities:
21
Last Updated:
December 19, 2025
Active Installs:
n/a
Published
Title
Fixed in
CVSS
Published
2025-10-03
Fixed in
CVSS
4.3 (medium)
Published
2025-02-12
Fixed in
CVSS
7.3 (high)
Published
2025-01-24
Fixed in
CVSS
5.3 (medium)
Published
2024-12-11
Fixed in
CVSS
4.3 (medium)
Published
2024-03-20
Fixed in
CVSS
6.4 (medium)
Published
2024-03-20
Fixed in
CVSS
7.2 (high)
Published
2024-03-20
Title
Avada < 7.11.7 - Unauthenticated Sensitive Information Exposure via Form Uploads Directory Listing
Fixed in
CVSS
5.3 (medium)
Published
2024-03-20
Title
Avada < 7.11.7 - Authenticated (Contributor+) Server-Side Request Forgery via form_to_url_action
Fixed in
CVSS
6.4 (medium)
Published
2024-02-28
Fixed in
CVSS
8.8 (high)
Published
2024-01-29
Fixed in
CVSS
4.3 (medium)
Published
2024-01-29
Fixed in
CVSS
7.2 (high)
Published
2024-01-29
Fixed in
CVSS
8.5 (high)
Published
2024-01-29
Fixed in
CVSS
6.6 (medium)
Published
2022-10-20
Fixed in
CVSS
8.8 (high)
Published
2022-04-19
Fixed in
CVSS
8.6 (high)
Published
2021-09-13
Fixed in
CVSS
6.1 (medium)
Published
2021-09-10
Fixed in
CVSS
n/a
Published
2020-05-01
Fixed in
CVSS
8.5 (high)
Published
2017-04-26
Fixed in
CVSS
8.8 (high)
Published
2015-02-11
Fixed in
CVSS
7.5 (high)
Published
2014-11-30
Fixed in
CVSS
9.4 (critical)