CVE-2024-12335
Avada Builder <= 3.11.12 - Authenticated (Contributor+) Protected Post Disclosure
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The Avada (Fusion) Builder plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.11.12 via the handle_clone_post() function and the 'fusion_blog' shortcode and due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with contributor-level access and above, to extract data from password protected, private, or draft posts that they should not have access to.
El complemento Avada (Fusion) Builder para WordPress es vulnerable a la exposición de información en todas las versiones hasta la 3.11.12 incluida a través de la función handle_clone_post() y el código corto 'fusion_blog' y debido a restricciones insuficientes sobre qué publicaciones se pueden incluir. Esto hace posible que atacantes autenticados, con acceso de nivel de colaborador y superior, extraigan datos de publicaciones protegidas con contraseña, privadas o borradores a las que no deberían tener acceso.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2024-12-06 CVE Reserved
- 2024-12-24 CVE Published
- 2024-12-26 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-639: Authorization Bypass Through User-Controlled Key
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://avada.com | ||
https://www.wordfence.com/threat-intel/vulnerabilities/id/4181dcad-b5bd-46db-b47c-3cdee427123c?source=cve |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Themefusion Search vendor "Themefusion" | Avada (Fusion) Builder Search vendor "Themefusion" for product "Avada (Fusion) Builder" | <= 3.11.12 Search vendor "Themefusion" for product "Avada (Fusion) Builder" and version " <= 3.11.12" | en |
Affected
|