Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-97340— Avada | Website Builder For WordPress & WooCommerce <= 7.16.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'author_facebook' User Profile Field

Quick assessment

Affected
ThemeFusion Avada | Website Builder For WordPress & WooCommerce
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

WordPress 上的 Avada Avada 主题通过 过滤器注册这些字段,并在作者归档页面中,使用 函数将这些字段嵌入到 标签的 属性中(该函数位于 方法内)。 仅转义 HTML 元字符,但并未阻止危险 URL 协议(如 )的使用。 因此,拥有订阅者(Subscriber)级别及以上权限的已认证攻击者,可以在其他用户访问其作者页面并点击所注入的社交图标时,注入并执行任意 Web 脚本。需要注意的是,此攻击需要用户手动点击图标,并且站点必须将“在新窗口中打开社交图标”(Open Social Icons in

CVSS 6.4 · Medium EPSS 0.16% · P4

Possible ATT&CK Techniques 1 AI

T1189 · Drive-by Compromise

Affected Version Matrix 1

VendorProduct Version RangeStatus
ThemeFusion Avada | Website Builder For WordPress & WooCommerce ≤ 7.16.1 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-97340

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Avada | Website Builder For WordPress & WooCommerce <= 7.16.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'author_facebook' User Profile Field
Source: CVE Program / CVE List V5
Vulnerability Description
The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Stored Cross-Site Scripting via the user profile 'Author Page' social link contact-method fields (author_facebook, author_twitter, author_linkedin, author_dribble, author_whatsapp, author_email) in versions up to, and including, 7.16.1. Avada registers these fields through the user_contactmethods filter and, on the author archive, emits them inside an anchor href using only esc_attr() in Fusion_Social_Icon::get_markup(), which escapes HTML metacharacters but does not reject dangerous URL schemes such as javascript:. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses their author page and clicks the injected social icon (a click is required, and the site must have 'Open Social Icons in a New Window' set to Off so the browser doesn't block the javascript: URL from opening in a new tab).
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
ThemeFusion Avada | Website Builder For WordPress & WooCommerce 0 ~ 7.16.1 -

II. Public POCs for CVE-2026-97340

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-97340

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-97340 (1)

Security Blog Posts for CVE-2026-97340 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-97340

No comments yet


Leave a comment