Skip to main content

Software intelligence

Avada vulnerabilities

24 tracked advisories · slug Avada

Important: Avada appearing in this catalog does not mean your website is affected. Exposure depends on your installed version. How SiteRespond intelligence works

Tracked advisories

24

Latest advisory

25 August 2026

CISA KEV matches

0

In this WordPress feed

WordPress slug

Avada

Theme

What this means for Avada

This catalog lists 24 known advisories affecting Avada. The most recent was published on 25 August 2026. If you use this software, compare your installed version against the affected ranges on each advisory and update to a fixed release outside those ranges. SiteRespond Defence checks your actual installed version when the plugin is connected — listing here does not by itself mean your site is vulnerable.

Latest issues

  • Avada <= 7.16 and Fusion Builder <= 3.16 - Unauthenticated Remote Code Execution via Arbitrary File Write

    May allow attackers to run arbitrary code on the server if exploited.

    Published 25 August 2026

  • Avada <= 3.15.3 - Authenticated (Contributor+) PHP Object Injection

    This advisory describes a other issue in the affected software. Review the source advisory and your installed version to assess exposure.

    Published 15 June 2026

  • Avada < 7.13.2 - Cross-Site Request Forgery

    May trick authenticated users into performing unintended actions.

    Published 22 April 2026

Vulnerability types

  • Cross-site scripting5
  • Remote code execution4
  • CSRF4
  • SQL injection1

Authentication (inferred from titles)

  • Unauthenticated4
  • Authenticated10
  • Unspecified10

Advisory history

Known Avada advisories published by month.

All advisories

1018 of 24

2 / 2

Check whether your installed version is affected

SiteRespond Defence matches your installed Avada version against this catalog when the Defence plugin is connected to your WordPress site.