CVE-2017-18607: Theme-Fusion Avada
High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.
The avada theme before 5.1.5 for WordPress has CSRF.
Affected products
- Theme-Fusion Avada: before 5.1.5 (fixed in 5.1.5)
Published 2019-09-10. Last modified 2026-06-17.