Input validation vulnerability in Avada | Website Builder For WordPress & WooCommerce 7.11.6

The Avada theme for WordPress has a security issue called SQL Injection, which affects all versions up to 7.11.6. This is because the ‘entry’ parameter is not properly protected and the existing SQL query is not prepared enough. This means that attackers who have editor-level access or higher can add their own SQL queries to the existing ones and access sensitive information from the website’s database.

Detected in:

Avada | Website Builder For WordPress & WooCommerce fixed vulnerable versions: >= * <= 7.11.6

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.