CVE-2024-1468

Avada | Website Builder For WordPress & WooCommerce <= 7.11.4 - Authenticated (Contributor+) Arbitrary File Upload

The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajax_import_options() function in all versions up to, and including, 7.11.4. This makes it possible for authenticated attackers, with contributor-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.


We have discovered 85,386 live websites that are affected by CVE-2024-1468.

Run a Free Instant Scan




Affected Software

Product  Avada
Category Wordpress Themes
Vulnerable Domains85,386 live websites (60% of Avada install base)
Vulnerable Versions
  • from 0 through 7.11.4
Vulnerable Versions Count121 versions ( 86% of all versions)


Common Weakness Enumeration

CWE-434 Unrestricted Upload of File with Dangerous Type



Details

  • Published - Feb 29, 2024
  • Updated - Apr 8, 2026

Credits

  • Muhammad Zeeshan (finder)

Website Distribution by Country

Number of websites using CVE-2024-1468
United States24,751 websites



Germany11,062 websites
Italy5,312 websites
France4,671 websites
GB4,332 websites
Spain3,449 websites
Netherlands3,384 websites
Canada2,064 websites
Australia1,787 websites
Poland1,407 websites

Website Distribution by TLD

Number of websites using CVE-2024-1468
.com34,796 websites
.de7,031 websites
.org3,724 websites
.it3,633 websites
.nl3,073 websites
.co.uk2,782 websites
.fr1,890 websites
.com.au1,711 websites
.net1,539 websites
.es1,477 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-1468

Top websites that are affected by CVE-2024-1468. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*************.**.za South Africa*,***
************.com Germany**,***
************.com United States**,***
***********.com United States**,***
********.nl Belgium**,***
******************.org United States**,***
***********.***.de Germany**,***
***********.com United States**,***
**************.org United States**,***
**********.com United States**,***
See full domain list

FAQ

CVE-2024-1468 is Unrestricted Upload of File with Dangerous Type in Avada
A total of 85,386 websites have been identified as vulnerable to CVE-2024-1468, based on global website indexing conducted by WebTechSurvey.
The Avada is affected by the CVE-2024-1468 vulnerability.
Avada versions up to and including 7.11.4 are vulnerable to CVE-2024-1468.