CVE-2024-1668: Avada <= 7.11.5 - Authenticated(Contributor+) Sensitive Information Exposure via Form Entries
The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Sensitive Information Exposure in versions up to and including 7.11.5 via the form entries page. This makes it possible for authenticated attackers, with contributor access and above, to view the contents of all form submissions, including fields that are obfuscated (such as the contact form's "password" field).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1668?
CVE-2024-1668 is classified as a medium severity vulnerability due to its ability to expose sensitive information to authenticated attackers.
How do I fix CVE-2024-1668?
To fix CVE-2024-1668, update the Avada theme to version 7.11.6 or later.
Who is affected by CVE-2024-1668?
CVE-2024-1668 affects users of the Avada Website Builder for WordPress and WooCommerce using versions up to and including 7.11.5.
What types of information can be exposed due to CVE-2024-1668?
CVE-2024-1668 allows authenticated users with contributor access and above to view sensitive information from form entries.
When was CVE-2024-1668 disclosed?
CVE-2024-1668 was disclosed in early 2024, highlighting a security flaw in the Avada theme.