Themes Vulnerabilities

Avada < 7.11.2 - Subscriber+ Portfolio Permalinks Creation

Description

The theme is vulnerable to unauthorized modification of data due to a missing capability check, allowing any authenticated attackers, with such as subscriber and above, to save Portfolio permalinks.

Affects Themes

Fixed in 7.11.2
Fixed in 7.11.2

References

Classification

Type
INCORRECT AUTHORISATION
CWE

Miscellaneous

Original Researcher
Rafie Muhammad
Verified
No

Timeline

Publicly Published
2024-01-29 (about 2 years ago)
Added
2024-01-30 (about 2 years ago)
Last Updated
2024-01-30 (about 2 years ago)

Other