Avada
cpe:2.3:a:theme-fusion:avada:*:*:*:*:wordpress:*:*
- <= 7.11.13
A vulnerability allowing arbitrary shortcode execution exists in the Avada WordPress theme, specifically in versions prior to and including 7.11.13. This issue arises because the theme permits users to execute actions without proper validation, allowing unauthenticated attackers to run arbitrary shortcodes.
Exploitation of this vulnerability could lead to unauthorized execution of shortcodes, potentially allowing attackers to execute malicious actions or code on the affected WordPress site.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.