CVE-2024-1668: Avada <= 7.11.5 - Authenticated(Contributor+) Sensitive Information Exposure via Form Entries

Published Mar 13, 2024
·
Updated

The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Sensitive Information Exposure in versions up to and including 7.11.5 via the form entries page. This makes it possible for authenticated attackers, with contributor access and above, to view the contents of all form submissions, including fields that are obfuscated (such as the contact form's "password" field).

Affected Software

2 affected components
Theme-fusion Avada Wordpress<7.11.6
Avada Website Builder<=7.11.5

Event History

Mar 13, 2024
CVE Published
via MITRE·03:32 PM
Data Sourced
via MITRE·03:32 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2024-1668?

CVE-2024-1668 is classified as a medium severity vulnerability due to its ability to expose sensitive information to authenticated attackers.

2

How do I fix CVE-2024-1668?

To fix CVE-2024-1668, update the Avada theme to version 7.11.6 or later.

3

Who is affected by CVE-2024-1668?

CVE-2024-1668 affects users of the Avada Website Builder for WordPress and WooCommerce using versions up to and including 7.11.5.

4

What types of information can be exposed due to CVE-2024-1668?

CVE-2024-1668 allows authenticated users with contributor access and above to view sensitive information from form entries.

5

When was CVE-2024-1668 disclosed?

CVE-2024-1668 was disclosed in early 2024, highlighting a security flaw in the Avada theme.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203