What the vulnerability does
01Description
Contributor Broken Access Control in Avada Custom Branding <= 1.2 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Contributor Broken Access Control in Avada Custom Branding <= 1.2 versions.
Explanation of Vulnerability in Simple Terms
Avada Custom Branding versions up to 1.2 lack proper authorization checks, allowing authenticated users with low privileges to view sensitive branding configuration data they should not access. The vulnerability requires a valid user account but no special interaction. This affects confidentiality only; data cannot be modified or the site disrupted.
What an attacker can do
Read branding configuration data that should be restricted to administrators.
Potential impact on your site
Unauthorized users can access sensitive branding settings; no data loss or site disruption risk.
Conditions required to exploit
Attacker must have a valid user account with low-level privileges on the site.
Key dates
External resources
Related vulnerabilities