The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajax_import_options() function in all versions up to, and including, 7.11.4. This makes it possible for authenticated attackers, with contributor-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
We have discovered 85,386 live websites that are affected by CVE-2024-1468.
| Product | |
| Category | Wordpress Themes |
| Vulnerable Domains | 85,386 live websites (60% of Avada install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 121 versions ( 86% of all versions) |
| 24,751 websites | |
| 11,062 websites | |
| 5,312 websites | |
| 4,671 websites | |
| 4,332 websites | |
| 3,449 websites | |
| 3,384 websites | |
| 2,064 websites | |
| 1,787 websites | |
| 1,407 websites |
| .com | 34,796 websites |
| .de | 7,031 websites |
| .org | 3,724 websites |
| .it | 3,633 websites |
| .nl | 3,073 websites |
| .co.uk | 2,782 websites |
| .fr | 1,890 websites |
| .com.au | 1,711 websites |
| .net | 1,539 websites |
| .es | 1,477 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *************.**.za | *,*** | ||
| ************.com | **,*** | ||
| ************.com | **,*** | ||
| ***********.com | **,*** | ||
| ********.nl | **,*** | ||
| ******************.org | **,*** | ||
| ***********.***.de | **,*** | ||
| ***********.com | **,*** | ||
| **************.org | **,*** | ||
| **********.com | **,*** |
FAQ