CVE-2024-12335: Avada Builder <= 3.11.12 - Authenticated (Contributor+) Protected Post Disclosure
The Avada (Fusion) Builder plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.11.12 via the handleclonepost() function and the 'fusionblog' shortcode and due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with contributor-level access and above, to extract data from password protected, private, or draft posts that they should not have access to.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12335?
CVE-2024-12335 has a medium severity rating due to the potential for information exposure.
How do I fix CVE-2024-12335?
To fix CVE-2024-12335, update the Avada (Fusion) Builder plugin to version 3.11.13 or later.
What causes CVE-2024-12335?
CVE-2024-12335 is caused by insufficient restrictions in the handle_clone_post() function related to the 'fusion_blog' shortcode.
Which versions of the Avada Builder are affected by CVE-2024-12335?
CVE-2024-12335 affects all versions of the Avada Builder plugin up to and including version 3.11.12.
Is the information exposed in CVE-2024-12335 sensitive?
Yes, the information exposed by CVE-2024-12335 could potentially include sensitive content from cloned posts.