CVE-2024-2340: Avada <= 7.11.6 - Unauthenticated Sensitive Information Exposure via Form Uploads Directory Listing
The Avada theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.11.6 via the '/wp-content/uploads/fusion-forms/' directory. This makes it possible for unauthenticated attackers to extract sensitive data uploaded via an Avada created form with a file upload mechanism.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2340?
The severity of CVE-2024-2340 is considered high due to the risk of sensitive information exposure to unauthenticated attackers.
How do I fix CVE-2024-2340?
To fix CVE-2024-2340, upgrade to Avada theme version 7.11.7 or later.
Who is affected by CVE-2024-2340?
CVE-2024-2340 affects all versions of the Avada theme for WordPress up to and including version 7.11.6.
What type of vulnerability is CVE-2024-2340?
CVE-2024-2340 is classified as a Sensitive Information Exposure vulnerability.
Can CVE-2024-2340 lead to data breaches?
Yes, CVE-2024-2340 can potentially lead to data breaches as it allows attackers to access sensitive data uploaded via Avada forms.