Known vulnerabilities in the Avada plugin
11 security advisories have been published for the Avada plugin. Each entry below states what an attacker can do, what privilege they need, and the version the issue was fixed in.
- Avada - PHP Object Injection (CVE-2026-12256) HIGH
- Avada - Security Vulnerability (CVE-2024-13346) HIGH
- Avada - Cross-Site Scripting (XSS) (CVE-2024-5628) MEDIUM
- Avada - SQL Injection (CVE-2024-2344) HIGH
- Avada - Server-Side Request Forgery (SSRF) (CVE-2024-2343) MEDIUM
- Avada - Arbitrary File Upload (CVE-2024-2340) MEDIUM
- Avada - Cross-Site Scripting (XSS) (CVE-2024-2311) MEDIUM
- Avada - Information Disclosure (CVE-2024-1668) MEDIUM
- Avada - Remote Code Execution (CVE-2024-1468) HIGH
- Avada - Cross-Site Request Forgery (CSRF) (CVE-2022-41996) HIGH
- Avada - Broken Access Control (CVE-2022-1386) CRITICAL