- Description
- The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 7.11.13. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
- Source
- security@wordfence.com
- NVD status
- Analyzed
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
- security@wordfence.com
- CWE-94
- Hype score
- Not currently trending
CVE-2024-13346 (CVSS:7.3, HIGH) is Awaiting Analysis. The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to arbitrary shortcode executi..https://t.co/VjIN0FygLZ #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre
@cracbot
18 Feb 2025
13 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CVE-2024-13346 🔴 HIGH (7.3) 🏢 ThemeFusion - Avada | Website Builder For WordPress & WooCommerce 🏗️ * https://t.co/vP3EMFp9Vt
@JdjdFjjf1829205
13 Feb 2025
19 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CVE-2024-13346 🔴 HIGH (7.3) 🏢 ThemeFusion - Avada | Website Builder For WordPress & WooCommerce 🏗️ * 🔗 https://t.co/GgoB2TLBI2 🔗 https://t.co/fkKMleoVcE #CyberCron #VulnAlert https://t.co/6fJHOqK6sE
@cybercronai
13 Feb 2025
20 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2024-13346 The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 7.11.… https://t.co/XeTI4Km5XY
@CVEnew
13 Feb 2025
116 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2024-13346 Unauthenticated Arbitrary Shortcode Execution in Avada WordPress Theme https://t.co/Tmc6ouWaGL Vulnerability Notification: https://t.co/xhLrNnfyrO
@VulmonFeeds
13 Feb 2025
48 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:theme-fusion:avada:*:*:*:*:*:wordpress:*:*",
"vulnerable": true,
"matchCriteriaId": "7A55AA17-687D-44C8-9F5D-4FB89EEE1BBD",
"versionEndExcluding": "7.11.14"
}
],
"operator": "OR"
}
]
}
]