Support Us — Your donation helps us keep running

Goal: 1000 CNY,Raised: 1000 CNY

100.0%

themefusion — Vulnerabilities & Security Advisories 36

Browse all 36 CVE security advisories affecting themefusion. AI-powered Chinese analysis, POCs, and references for each vulnerability.

CVE IDTitleCVSSSeverityPaused
CVE-2025-58922 WordPress Avada theme < 7.13.2 - Cross Site Request Forgery (CSRF) vulnerability — AvadaCWE-352 4.3 Medium2026-04-22
CVE-2026-1509 Avada (Fusion) Builder <= 3.15.1 - Authenticated (Subscriber+) Limited Arbitrary WordPress Action Execution — Avada (Fusion) BuilderCWE-94 5.4 Medium2026-04-15
CVE-2026-1541 Avada (Fusion) Builder <= 3.15.1 - Authenticated (Subscriber+) Sensitive Information Exposure via Insecure Direct Object Reference — Avada (Fusion) BuilderCWE-639 4.3 Medium2026-04-15
CVE-2026-32542 WordPress Fusion Builder plugin < 3.15.0 - Reflected Cross Site Scripting (XSS) vulnerability — Fusion BuilderCWE-79 6.1 -2026-03-25
CVE-2026-32452 WordPress Fusion Builder plugin < 3.15.0 - Broken Access Control vulnerability — Fusion BuilderCWE-862 9.1 -2026-03-13
CVE-2026-32454 WordPress Avada Core plugin < 5.15.0 - Cross Site Scripting (XSS) vulnerability — Avada CoreCWE-79 6.1 -2026-03-13
CVE-2026-32453 WordPress Avada Core plugin < 5.15.0 - Broken Access Control vulnerability — Avada CoreCWE-862 9.1 -2026-03-13
CVE-2026-32451 WordPress Fusion Builder plugin < 3.15.0 - Broken Access Control vulnerability — Fusion BuilderCWE-862 9.1 -2026-03-13
CVE-2026-25472 WordPress Fusion Builder plugin <= 3.14.1 - Cross Site Scripting (XSS) vulnerability — Fusion BuilderCWE-79 5.4AIMediumAI2026-02-19
CVE-2025-64634 WordPress Avada theme <= 7.13.2 - Broken Access Control vulnerability — AvadaCWE-862 5.3 Medium2025-12-16
CVE-2025-49940 WordPress Fusion Builder plugin <= 3.13.2 - Cross Site Scripting (XSS) vulnerability — Fusion BuilderCWE-79 6.1AIMediumAI2025-10-22
CVE-2025-6747 Avada (Fusion) Builder <= 3.12.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode — Avada (Fusion) BuilderCWE-79 6.4 Medium2025-07-16
CVE-2025-24748 WordPress Avada theme <= 7.11.10 - Broken Access Control vulnerability — AvadaCWE-862 5.3 Medium2025-07-04
CVE-2025-1665 Avada Builder <= 3.11.14 - Authenticated (Contributor+) Stored Cross-Site Scripting — Avada (Fusion) BuilderCWE-79 6.4 Medium2025-04-01
CVE-2024-13345 Avada Builder <= 3.11.13 - Unauthenticated Arbitrary Shortcode Execution — Avada (Fusion) BuilderCWE-94 7.3 High2025-02-13
CVE-2024-13346 Avada Theme <= 7.11.13 - Unauthenticated Arbitrary Shortcode Execution — Avada | Website Builder For WordPress & WooCommerceCWE-94 7.3 High2025-02-13
CVE-2024-12477 Avada Builder <= 3.11.11 - Authenticated (Contributor+) Stored Cross-Site Scripting in Multiple Widgets — Avada (Fusion) BuilderCWE-79 6.4 Medium2025-01-22
CVE-2024-12335 Avada Builder <= 3.11.12 - Authenticated (Contributor+) Protected Post Disclosure — Avada (Fusion) BuilderCWE-639 4.3 Medium2024-12-25
CVE-2024-54357 WordPress Avada theme <= 7.11.10 - Cross Site Request Forgery (CSRF) vulnerability — AvadaCWE-352 4.3 Medium2024-12-16
CVE-2024-5628 Avada | Website Builder For WordPress & eCommerce <= 3.11.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via fusion_button Shortcode — Avada (Fusion) BuilderCWE-79 6.4 Medium2024-09-13
CVE-2023-39312 WordPress Avada theme <= 7.11.1 - Auth. Unrestricted Zip Extraction vulnerability — AvadaCWE-862 9.1 Critical2024-06-19
CVE-2023-39310 WordPress Avada Builder plugin <= 3.11.1 - Authenticated Broken Access Control vulnerability — Fusion BuilderCWE-862 5.4 Medium2024-06-19
CVE-2023-39922 WordPress Avada theme <= 7.11.1 - Authenticated Broken Access Control vulnerability — AvadaCWE-862 4.3 Medium2024-06-19
CVE-2024-2311 Avada <= 7.11.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode — Avada | Website Builder For WordPress & WooCommerceCWE-79 6.4 Medium2024-04-09
CVE-2024-2344 Avada <= 7.11.6 - Authenticated (Admin+) SQL Injection via entry — Avada | Website Builder For WordPress & WooCommerceCWE-89 7.2 High2024-04-09
CVE-2024-2340 Avada <= 7.11.6 - Unauthenticated Sensitive Information Exposure via Form Uploads Directory Listing — Avada | Website Builder For WordPress & WooCommerceCWE-548 5.3 Medium2024-04-09
CVE-2024-2343 Avada <= 7.11.6 - Authenticated (Contributor+) Server-Side Request Forgery via form_to_url_action — Avada | Website Builder For WordPress & WooCommerceCWE-918 6.4 Medium2024-04-09
CVE-2023-39309 WordPress Avada Builder plugin <= 3.11.1 - Auth. SQL Injection vulnerability — Fusion BuilderCWE-89 8.5 High2024-03-28
CVE-2023-39313 WordPress Avada theme <= 7.11.1 - Authenticated Server Side Request Forgery (SSRF) vulnerability — AvadaCWE-918 7.7 High2024-03-28
CVE-2023-39311 WordPress Avada Builder plugin <= 3.11.1 - Cross Site Request Forgery (CSRF) vulnerability — Fusion BuilderCWE-352 7.1 High2024-03-27

This page lists every published CVE security advisory associated with themefusion. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.