Themes Vulnerabilities

Enfold Theme < 4.8.4 - Reflected Cross-Site Scripting (XSS)

Description

The Enfold theme was vulnerable to Reflected Cross-Site Scripting (XSS). The vulnerability is present on Enfold versions previous than 4.8.4 which use Avia Page Builder.

Proof of Concept

Affects Themes

Fixed in 4.8.4

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
David Álvarez Robles, Francisco Díaz-Pache Alonso & Sergio Corral Cristo
Submitter
David Álvarez Robles
Submitter website
Submitter twitter
Verified
No

Timeline

Publicly Published
2021-09-06 (about 4 years ago)
Added
2021-09-09 (about 4 years ago)
Last Updated
2022-04-12 (about 3 years ago)

Other