VYPR
Unrated severityNVD Advisory· Published Oct 27, 2022· Updated Apr 28, 2026

WordPress Avada premium theme <= 7.8.1 - Cross-Site Request Forgery (CSRF) vulnerability

CVE-2022-41996

Description

Cross-Site Request Forgery (CSRF) vulnerability in ThemeFusion Avada premium theme versions <= 7.8.1 on WordPress leading to arbitrary plugin installation/activation.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

CSRF in Avada theme <=7.8.1 on WordPress allows attackers to install/activate arbitrary plugins via crafted requests.

Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the ThemeFusion Avada premium theme for WordPress, versions 7.8.1 and earlier. The issue allows an attacker to perform unauthorized actions, such as installing or activating arbitrary plugins, by tricking an authenticated administrator into visiting a malicious page [1].

Exploitation

To exploit the vulnerability, an attacker must craft a malicious link or form that submits a request to the Avada theme's admin functionality. The victim must be logged in as an administrator and interact with the crafted request (e.g., by clicking a link). No other authentication or network position is required beyond the standard web access.

Impact

Successful exploitation enables the attacker to install or activate any WordPress plugin without authorization. This can lead to full site compromise, as the attacker could install malicious plugins that execute arbitrary code, steal data, or further escalate privileges.

Mitigation

The vulnerability is fixed in Avada version 7.8.2 and later. Users should update their theme to the latest version available. The changelog [1] provides details on the update. If upgrade is not possible, consider restricting access to WordPress admin pages or employing CSRF protection mechanisms.

AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • WordPress/Avadallm-fuzzy
    Range: <=7.8.1
  • ThemeFusion/Avada (premium WordPress theme)v5
    Range: <= 7.8.1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.