Avada WordPress Theme Shortcode Execution Vulnerability

Vulnerability

A vulnerability allowing arbitrary shortcode execution exists in the Avada WordPress theme, specifically in versions prior to and including 7.11.13. This issue arises because the theme permits users to execute actions without proper validation, allowing unauthenticated attackers to run arbitrary shortcodes.

Impact

Exploitation of this vulnerability could lead to unauthorized execution of shortcodes, potentially allowing attackers to execute malicious actions or code on the affected WordPress site.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
6.4
impact
1.3
exploitability
7.6
remediation
0.0
relevance
0.0
threat
1.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.