Vulnerabilities > Theme Fusion
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-05-16 | CVE-2022-1386 | The Fusion Builder WordPress plugin before 3.6.2, used in the Avada theme, does not validate a parameter in its forms which could be used to initiate arbitrary HTTP requests. | 9.8 |
2019-09-10 | CVE-2017-18607 | Cross-Site Request Forgery (CSRF) vulnerability in Theme-Fusion Avada The avada theme before 5.1.5 for WordPress has CSRF. | 8.8 |
2019-09-10 | CVE-2017-18606 | Cross-site Scripting vulnerability in Theme-Fusion Avada The avada theme before 5.1.5 for WordPress has stored XSS. | 6.1 |