Sceawere

Vulnerability Detail

CVE-2026-84925UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Avada Reflected XSS Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.1
Creation Date
17h ago
Vendor
ThemeFusion
Product
Avada | Website Builder For WordPress & WooCommerce
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'lang' parameter in all versions up to, and including, 7.16.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. The injected value is propagated through Fusion_Multilingual::set_active_language() and concatenated into a URL by Fusion_Settings::get_setting_link() without applying urlencode(), esc_url(), or esc_attr() before being echoed raw into a double-quoted href attribute in the post editor metabox.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.1",
  "pubDate": "2026-10-02T06:16:41.587Z",
  "pubdate": "2026-10-02T06:16:41.587Z",
  "executiveSummary": "The Avada website builder for WordPress and WooCommerce, in versions up to and including 7.16.1, contains a critical Reflected Cross-Site Scripting (XSS) vulnerability. The flaw resides in the theme's handling of the 'lang' parameter, which fails to adequately sanitize input before outputting it to the user's browser.\nThis vulnerability allows unauthenticated attackers to execute arbitrary JavaScript within the context of a victim's session. By crafting a malicious URL containing a scripted payload, an attacker can trick an authenticated user, such as an administrator, into clicking a link. Once executed, the script operates with the permissions of the victim, potentially leading to unauthorized administrative actions, account takeover, or session hijacking.\nThe root cause is a failure to sanitize input or escape output during the generation of HTML attributes within the post editor metabox. Due to the wide usage of the Avada theme, this vulnerability poses a significant risk to the integrity and security of affected WordPress installations. There are no authentication requirements for an attacker to initiate this attack, relying solely on social engineering to induce a user to interact with the malicious payload.",
  "technicalDetails": "The vulnerability is a classic Reflected Cross-Site Scripting (XSS) flaw stemming from improper data handling in the Avada theme's multilingual integration logic. The primary point of injection is the 'lang' parameter processed by the Fusion_Multilingual::set_active_language() function.\nThe attack flow begins when an unauthenticated attacker crafts a malicious URL containing a JavaScript payload within the 'lang' parameter. When a victim accesses this URL, the theme processes the input through Fusion_Multilingual::set_active_language(). Crucially, the theme subsequently passes this input to Fusion_Settings::get_setting_link(), which performs string concatenation to form a URL for a double-quoted href attribute inside a WordPress post editor metabox.\nThe technical failure occurs because the developer neglected to apply essential security functions—specifically urlencode(), esc_url(), or esc_attr()—before echoing the variable directly into the HTML document. Because the payload is placed inside an attribute that is rendered in the browser without proper context-aware encoding, the browser interprets the injected JavaScript as executable code rather than a static string. By terminating the attribute context (e.g., using a closing quote or other attribute-breaking characters), the attacker can inject event handlers like 'onmouseover' or 'onerror', or use 'javascript:' pseudo-protocols to execute arbitrary code.\nThe impact is significant, as the code executes in the victim's browser session. If the victim is an administrator, the script can perform any action available to that user, including the creation of rogue administrator accounts, modifying site settings, or installing malicious plugins. Because the vulnerability requires the victim to click a specially crafted link, it is categorized as a client-side attack that leverages the trust established between the user's browser and the WordPress application. The lack of output encoding at the point of injection facilitates a bypass of typical cross-site scripting filters if they are not explicitly configured to inspect attribute-level data."
}
CVE-2026-84925: Avada Reflected XSS Vulnerability (MEDIUM Severity, CVSS: 6.1) | Sceawere