S4E just found a high top 10 tcp port service scan
medium·Product Based Web Vulnerabilities·Updated Jul 8, 2024

CVE-2024-2340 Scanner

CVE-2024-2340 scanner - Information Disclosure vulnerability in Avada

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.6k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-2340
5.3
CVSSmedium
Exploitable remotely over the internet · no authentication required.

The Avada theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.11.6 via the '/wp-content/uploads/fusion-forms/' directory. This makes it possible for unauthenticated attackers to extract sensitive data uploaded via an Avada created form with a file upload mechanism.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Avada | Website Builder For WordPress & WooCommerceby ThemeFusion
0
avadaby theme-fusion
AFFECTED< 7.11.7SAFE ✓≥ 7.11.7
Updated Aug 22, 2026View on NVD →
Detail

Avada is a popular WordPress theme used for building websites by designers, developers, and businesses. It offers a wide range of customization options and is known for its user-friendly interface. The theme is used in various industries for creating visually appealing and functional websites. Avada integrates with various plugins and tools to enhance website functionality. Due to its extensive use, security in Avada is crucial to prevent data breaches and unauthorized access.

The Avada theme for WordPress is vulnerable to Sensitive Information Exposure. This vulnerability exists in versions up to, and including, 7.11.6. It allows unauthenticated attackers to access sensitive data uploaded via forms created by Avada. The issue resides in the '/wp-content/uploads/fusion-forms/' directory, exposing sensitive information.

The vulnerability is present in the Avada theme’s handling of file uploads in forms. Specifically, files uploaded via Avada-created forms are stored in the '/wp-content/uploads/fusion-forms/' directory. This directory is accessible to unauthenticated users, who can view and extract sensitive information. The endpoint '/wp-content/uploads/fusion-forms/' lacks proper access controls, leading to information disclosure. Attackers can leverage this vulnerability by simply navigating to the specified directory.

Exploiting this vulnerability can lead to significant data breaches. Attackers can access sensitive information such as personal data, business documents, and other confidential files. This can result in identity theft, financial loss, and damage to the affected organization's reputation. The disclosed information can be used for further attacks, such as phishing or social engineering.

Join the S4E platform to ensure your digital assets are secure from vulnerabilities like this. Our comprehensive scanning services detect and report vulnerabilities in your systems, helping you maintain a robust security posture. Benefit from our easy-to-use interface, detailed reports, and expert guidance on remediation. Protect your business from potential threats and stay ahead of cyber attackers. Become a member today and secure your digital world with confidence.

References:

Solution Advice
  • Update Avada theme to version 7.11.7 or later.
  • Ensure proper access controls are in place for the '/wp-content/uploads/fusion-forms/' directory.
  • Regularly review and monitor file upload directories for unauthorized access.
  • Implement security measures to restrict access to sensitive data directories.
  • Educate users and administrators on secure file handling and data protection practices.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2024-2340 scanner - Information Disclosure vulnerability in Avada S4E