The Avada Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.11.13. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
We have discovered 84,288 live websites that are affected by CVE-2024-13345.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 84,288 live websites (43% of Avada Builder install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 42 versions ( 78% of all versions) |
| 23,658 websites | |
| 14,145 websites | |
| 4,843 websites | |
| 4,416 websites | |
| 4,142 websites | |
| 3,548 websites | |
| 3,120 websites | |
| 2,010 websites | |
| 1,744 websites | |
| 1,692 websites |
| .com | 32,912 websites |
| .de | 9,866 websites |
| .org | 3,838 websites |
| .it | 3,392 websites |
| .nl | 3,319 websites |
| .co.uk | 2,804 websites |
| .fr | 1,719 websites |
| .com.au | 1,565 websites |
| .ch | 1,422 websites |
| .net | 1,400 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *************.**.za | *,*** | ||
| ************.com | **,*** | ||
| ************.com | **,*** | ||
| ************.com | **,*** | ||
| **********.gr | **,*** | ||
| ********.com | **,*** | ||
| ***********.com | **,*** | ||
| ********.nl | **,*** | ||
| ******************.org | **,*** | ||
| ****.org | **,*** |
FAQ