CVE-2025-64634: WordPress Avada theme <= 7.13.2 - Broken Access Control vulnerability
Published Dec 16, 2025
·Updated
Missing Authorization vulnerability in ThemeFusion Avada avada allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Avada: from n/a through <= 7.13.2.
Affected Software
3 affected components
ThemeFusion Avada<=7.13.1
wordpress/avada<=7.13.1
Theme-fusion Avada Wordpress<=7.13.1
Event History
Dec 16, 2025
CVE Published
via MITRE·08:12 AM
Data Sourced
via MITRE·08:12 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeaknessAffected Software
Sep 7, 58290
Event
via MITRE·12:28 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-64634?
CVE-2025-64634 is classified as a high-severity vulnerability due to missing authorization controls.
2
How do I fix CVE-2025-64634?
To fix CVE-2025-64634, update ThemeFusion Avada to version 7.13.2 or later to ensure proper access control.
3
What systems are affected by CVE-2025-64634?
CVE-2025-64634 affects ThemeFusion Avada version 7.13.1 and earlier.
4
What type of vulnerability is CVE-2025-64634?
CVE-2025-64634 is a missing authorization vulnerability allowing access to functionality not properly constrained by access control lists (ACLs).
5
Can CVE-2025-64634 lead to data breaches?
Yes, CVE-2025-64634 can potentially lead to data breaches by allowing unauthorized users access to restricted functionalities.