CVE-2025-24748: WordPress Avada theme <= 7.11.10 - Broken Access Control vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup All In One Slider Responsive allows SQL Injection. This issue affects All In One Slider Responsive: from n/a through 3.7.9.
Other sources
Missing Authorization vulnerability in ThemeFusion Avada avada.This issue affects Avada: from n/a through <= 7.11.10.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24748?
CVE-2025-24748 is classified as a high severity SQL Injection vulnerability.
How do I fix CVE-2025-24748?
To fix CVE-2025-24748, update the LambertGroup All In One Slider Responsive plugin to the latest version above 3.7.9.
What versions of All In One Slider Responsive are affected by CVE-2025-24748?
CVE-2025-24748 affects all versions of All In One Slider Responsive from n/a up to and including version 3.7.9.
What type of vulnerability is CVE-2025-24748?
CVE-2025-24748 is an SQL Injection vulnerability that allows attackers to manipulate SQL commands.
Can CVE-2025-24748 be exploited remotely?
Yes, CVE-2025-24748 can potentially be exploited remotely without authentication by an attacker.