Headline
CVE-2022-41996: WordPress Avada premium theme <= 7.8.1 - Cross-Site Request Forgery (CSRF) vulnerability - Patchstack
Cross-Site Request Forgery (CSRF) vulnerability in ThemeFusion Avada premium theme versions <= 7.8.1 on WordPress leading to arbitrary plugin installation/activation.
Verified
Fixed
8.8
CVSS 3.1 score High severity
Report
Monitoring Not reported to be exploited
Vulnerable versions
<= 7.8.1
PSID
ce884d29476d
Classification
Cross Site Request Forgery (CSRF)
OWASP Top 10
A5: Broken Access Control
Publicly disclosed
2022-10-20
Details
Cross-Site Request Forgery (CSRF) vulnerability Leading to Arbitrary Plugin Installation/Activation discovered by Dave Jong (Patchstack) in WordPress Avada theme (versions <= 7.8.1).
Solution
Update the WordPress Avada theme to the latest available version (at least 7.8.2).
References
Changelog