CVE-2024-1668
moderate-risk
Published 2024-03-13
The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Sensitive Information Exposure in versions up to and including 7.11.5 via the form entries page. This makes it possible for authenticated attackers, with contributor access and above, to view the contents of all form submissions, including fields that are obfuscated (such as the contact form's "password" field).
Do I need to act?
-
0.55% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
6
CVSS 6.5/10
Medium
NETWORK
/ LOW complexity
Affected Products (1)
Affected Vendors
References (4)
Third Party Advisory
https://gist.github.com/Xib3rR4dAr/91bd37338022b15379f393356d1056a1
Third Party Advisory
https://www.wordfence.com/threat-intel/vulnerabilities/id/cd224169-ae51-4af8-b6d...
Third Party Advisory
https://gist.github.com/Xib3rR4dAr/91bd37338022b15379f393356d1056a1
Third Party Advisory
https://www.wordfence.com/threat-intel/vulnerabilities/id/cd224169-ae51-4af8-b6d...
31
/ 100
moderate-risk
Severity
24/34 · High
Exploitability
2/34 · Minimal
Exposure
5/34 · Minimal