Cyber Posture

CVE-2024-13346

High

Published: 13 February 2025

Published
13 February 2025
Modified
24 February 2025
KEV Added
Patch
CVSS Score 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
EPSS Score 0.4129 97.4th percentile
Risk Priority 39 60% EPSS · 20% KEV · 20% CVSS

Description

The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 7.11.13. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

Security Summary

The Avada Website Builder theme for WordPress and WooCommerce is vulnerable to CVE-2024-13346, an arbitrary shortcode execution flaw affecting all versions up to and including 7.11.13. The vulnerability stems from the software permitting execution of an action without properly validating a supplied value before invoking the do_shortcode function, as classified under CWE-94. It carries a CVSS v3.1 base score of 7.3 (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L), indicating high severity due to its network accessibility and lack of prerequisites.

Unauthenticated attackers can exploit this remotely with low attack complexity, no privileges, and no user interaction required. Exploitation enables execution of arbitrary shortcodes, granting limited impacts on confidentiality, integrity, and availability, such as potential data disclosure, modification, or disruption via malicious shortcode payloads.

For mitigation, security practitioners should review the official Avada changelog at https://avada.com/documentation/avada-changelog/ and Wordfence threat intelligence at https://www.wordfence.com/threat-intel/vulnerabilities/id/1f2f390b-332b-452c-9fe7-ccd1a45390dd?source=cve, which detail patches and remediation steps.

Details

CWE(s)
CWE-94

Affected Products

theme-fusion
avada
≤ 7.11.14

References