Pricing
Case studies
Login
Start trial
Avada
ThemeFusion
Developer
N/A
Latest version
N/A
Downloads
N/A
Last updated
WordPress Theme
Active VDP
Report vulnerability
Vulnerabilities
Security Policy
Security Contributors
Vulnerability history
0 present
18 patched
9 Mitigation rules
Broken Access Control vulnerability
<= 7.13.2
03/10/2025
Unauthenticated Arbitrary Shortcode Execution vulnerability
<= 7.11.13
12/02/2025
Broken Access Control vulnerability
<= 7.11.10
24/01/2025
Cross Site Request Forgery (CSRF) vulnerability
<= 7.11.10
11/12/2024
Unauthenticated Sensitive Information Exposure via Form Uploads Directory Listing vulnerability
<= 7.11.6
21/03/2024
Authenticated (Admin+) SQL Injection via entry vulnerability
<= 7.11.6
21/03/2024
Authenticated (Contributor+) Server-Side Request Forgery via form_to_url_action vulnerability
<= 7.11.6
21/03/2024
Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode vulnerability
<= 7.11.6
21/03/2024
Authenticated(Contributor+) Sensitive Information Exposure via Form Entries vulnerability
<= 7.11.5
04/03/2024
Authenticated (Contributor+) Arbitrary File Upload vulnerability
<= 7.11.4
28/02/2024
Authenticated Arbitrary File Upload vulnerability
<= 7.11.1
10/08/2023
Authenticated Server Side Request Forgery (SSRF) vulnerability
<= 7.11.1
10/08/2023
Authenticated (Author+) Unrestricted Zip Extraction vulnerability
<= 7.11.1
10/08/2023
Authenticated Broken Access Control vulnerability
<= 7.11.1
10/08/2023
Cross-Site Request Forgery (CSRF) vulnerability
<= 7.8.1
20/10/2022
Unauthenticated Server-Side Request Forgery (SSRF) vulnerability
<= 7.6.1
19/04/2022
Arbitrary Post Creation, Edition and Deletion vulnerability
<= 6.2.2
01/05/2020
Stored Cross-Site Scripting (XSS) vulnerability
<= 6.2.2
01/05/2020