Medium severity6.5NVD Advisory· Published Mar 13, 2024· Updated Apr 8, 2026
CVE-2024-1668
CVE-2024-1668
Description
The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Sensitive Information Exposure in versions up to and including 7.11.5 via the form entries page. This makes it possible for authenticated attackers, with contributor access and above, to view the contents of all form submissions, including fields that are obfuscated (such as the contact form's "password" field).
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- gist.github.com/Xib3rR4dAr/91bd37338022b15379f393356d1056a1nvdThird Party Advisory
- www.wordfence.com/threat-intel/vulnerabilities/id/cd224169-ae51-4af8-b6de-706ed580ff8dnvdThird Party Advisory
News mentions
0No linked articles in our index yet.