What the vulnerability does
01Description
Server-Side Request Forgery (SSRF) vulnerability in ThemeFusion Avada.This issue affects Avada: from n/a through 7.11.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
What the vulnerability does
Server-Side Request Forgery (SSRF) vulnerability in ThemeFusion Avada.This issue affects Avada: from n/a through 7.11.1.
Explanation of Vulnerability in Simple Terms
Avada versions up to 7.11.1 contain a server-side request forgery vulnerability that allows authenticated users to make the site send HTTP requests to internal or external systems on their behalf. An attacker with low-level site access can retrieve sensitive data from internal services or interact with external APIs without authorization. The vulnerability requires valid site credentials but no user interaction.
What an attacker can do
Make the site send HTTP requests to internal systems or external URLs to read data or trigger actions.
Potential impact on your site
Authenticated attackers can access internal services, read sensitive data, or interact with external systems via your site.
Conditions required to exploit
Attacker must have a low-privilege site account (e.g., subscriber or contributor role).
Key dates
External resources
Related vulnerabilities