CVE-2023-39922: WordPress Avada theme <= 7.11.1 - Authenticated Broken Access Control vulnerability
Published Jun 19, 2024
·Updated
Missing Authorization vulnerability in ThemeFusion Avada.This issue affects Avada: from n/a through 7.11.1.
Affected Software
3 affected components
Theme-fusion Avada Wordpress<7.11.2
ThemeFusion Avada<=7.11.1
WordPress Avada<=7.11.1
Remediation
Information
Update to 7.11.2 or a higher version.
Event History
Jun 19, 2024
CVE Published
via MITRE·12:17 PM
Data Sourced
via MITRE·12:17 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
May 26, 57072
Event
via NVD·03:24 AM
Frequently Asked Questions
1
What is the severity of CVE-2023-39922?
CVE-2023-39922 is considered a critical vulnerability due to the potential for unauthorized actions within the ThemeFusion Avada theme.
2
How do I fix CVE-2023-39922?
To fix CVE-2023-39922, update the ThemeFusion Avada theme to the latest version beyond 7.11.1.
3
What versions of Avada are affected by CVE-2023-39922?
CVE-2023-39922 affects all versions of Avada from n/a up to and including 7.11.1.
4
Is there a workaround for CVE-2023-39922?
A temporary workaround for CVE-2023-39922 may involve restricting access to specific features until an update is applied.
5
Who can be impacted by CVE-2023-39922?
Users and administrators of WordPress sites utilizing affected versions of the Avada theme can be impacted by CVE-2023-39922.