Mmastodon TechnologyCybersecurity first seen 20 h ago, last 20 h ago, peak #12
Avada WordPress theme hit by reflected XSS vulnerability
Original: π¨ EUVD-2026-91174 π Score: 6.1/10 (CVSS v3.1) π¦ Product: Avada | Website Builder For WordPress & WooCommerce π’ Vendor: T
A medium-severity vulnerability, tracked as EUVD-2026-91174 with a CVSS score of 6.1, has been reported in Avada, the popular website builder theme for WordPress and WooCommerce from vendor ThemeFusion. The flaw is a reflected cross-site scripting issue, updated on 2026-10-02, allowing attackers to inject malicious scripts via crafted links. WordPress site owners using Avada are advised to update promptly.
Why now: Millions of sites run Avada, so administrators are checking whether they need to patch.
AvadaThemeFusionWordPressWooCommerce
Evidence
API: https://socialmediatrends-api.osmike.com/v1/trends/699560