Sceawere
Vulnerability Detail
CVE-2026-97340UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Avada Stored XSS via Social Links
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.4
- Creation Date
- 2h ago
- Vendor
- ThemeFusion
- Product
- Avada | Website Builder For WordPress & WooCommerce
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Stored Cross-Site Scripting via the user profile 'Author Page' social link contact-method fields (author_facebook, author_twitter, author_linkedin, author_dribble, author_whatsapp, author_email) in versions up to, and including, 7.16.1. Avada registers these fields through the user_contactmethods filter and, on the author archive, emits them inside an anchor href using only esc_attr() in Fusion_Social_Icon::get_markup(), which escapes HTML metacharacters but does not reject dangerous URL schemes such as javascript:. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses their author page and clicks the injected social icon (a click is required, and the site must have 'Open Social Icons in a New Window' set to Off so the browser doesn't block the javascript: URL from opening in a new tab).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.4",
"pubDate": "2026-10-10T08:17:08.307Z",
"pubdate": "2026-10-10T08:17:08.307Z",
"executiveSummary": "The Avada | Website Builder For WordPress & WooCommerce theme is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability affecting versions up to and including 7.16.1.\nThe flaw originates from improper input validation and insufficient output sanitization within the user profile social contact methods, specifically the author_facebook, author_twitter, author_linkedin, author_dribble, author_whatsapp, and author_email fields.\nAn authenticated attacker with at least Subscriber-level privileges can inject malicious JavaScript payloads into these fields. When these fields are rendered on an author archive page, the theme fails to neutralize dangerous URL schemes.\nSuccessful exploitation requires a user to click the manipulated social icon link under specific theme configuration settings (Open Social Icons in a New Window set to Off).\nThis vulnerability poses a significant risk, as it allows attackers to execute arbitrary scripts in the context of a victim's session, potentially leading to unauthorized actions, account takeover, or the exfiltration of sensitive information.\nThe scope of impact is confined to the WordPress environment where the Avada theme is active and configured in a vulnerable state.",
"technicalDetails": "The vulnerability resides in the implementation of the user_contactmethods filter within the Avada theme. The theme registers several social media contact fields that are stored within the WordPress user metadata.\nThe root cause of this security flaw is the misuse of the esc_attr() function within the Fusion_Social_Icon::get_markup() method. While esc_attr() is effective for neutralizing HTML metacharacters—thereby preventing the breaking out of the 'href' attribute context—it does not perform protocol validation or filtering for dangerous URI schemes, such as 'javascript:'.\nWhen a user with Subscriber access or higher modifies their profile, they can inject a payload such as 'javascript:alert(document.cookie)' into any of the vulnerable social link fields. Because the input is saved to the database without verification of the protocol, the malicious URI is stored persistently.\nThe attack flow proceeds as follows: First, the attacker authenticates with the WordPress site. Second, the attacker updates their user profile, inputting a 'javascript:' URI into one of the affected social link contact methods. Third, the WordPress site renders the author archive page for the attacker's account. Within the HTML output, the Fusion_Social_Icon::get_markup() method processes this metadata and emits an anchor tag where the 'href' attribute contains the attacker-supplied malicious payload.\nThe execution of the payload is triggered when a victim (e.g., an administrator or another user) navigates to the compromised author archive page and interacts with the social icon. The browser interprets the 'javascript:' scheme and executes the embedded code within the context of the victim's session.\nThis exploitation is conditional upon the theme's 'Open Social Icons in a New Window' setting. If this setting is disabled, the browser executes the script in the current window. If enabled, the browser behavior regarding 'javascript:' URLs in new windows may vary, but typically mitigates the risk by blocking the execution. Consequently, the impact includes unauthorized data access, session hijacking, and potential administrative privilege escalation if an administrator interacts with the link.\nThe vulnerability is present in all versions up to 7.16.1. No recursive filtering or URL scheme allowlisting is present to block non-HTTP/HTTPS protocols, resulting in the failure of the security control applied during output."
}