CVE-2022-41996

All FrameworksWordPressCWE-352CVE-2022-41996

CVE-2022-41996

State: PUBLISHED · Published: 2022-10-27 · Updated: 2025-02-20 · Assigner: Patchstack
Description
Cross-Site Request Forgery (CSRF) vulnerability in ThemeFusion Avada premium theme versions <= 7.8.1 on WordPress leading to arbitrary plugin installation/activation.
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2022/41xxx/CVE-2022-41996.json