The Avada | Website Builder For WordPress & WooCommerce...
Moderate severity
Unreviewed
Published
Apr 9, 2024
to the GitHub Advisory Database
•
Updated Jan 31, 2025
Description
Published by the National Vulnerability Database
Apr 9, 2024
Published to the GitHub Advisory Database
Apr 9, 2024
Last updated
Jan 31, 2025
The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.11.6 via the form_to_url_action function. This makes it possible for authenticated attackers, with contributor-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.
References