Medium · 4.5 WordPress CVE-2026-97340
Stored XSS in Avada WordPress Theme Author Profile Fields (CVE-2026-97340)
The Avada WordPress theme is affected by a stored cross-site scripting vulnerability in author profile social link fields, allowing authenticated users with Subscriber-level access to inject malicious scripts that execute on author archive pages.
AI summary
A stored cross-site scripting (XSS) vulnerability has been identified in Avada, a widely used WordPress theme for building websites and WooCommerce stores. The issue, tracked as CVE-2026-97340, affects the handling of author profile social link fields and can allow low-privileged authenticated users to inject scripts that run in the browsers of visitors to author archive pages.
What Happened
Avada registers custom contact-method fields on WordPress user profiles for social links, including fields for Facebook, Twitter, LinkedIn, Dribbble, WhatsApp, and email. These values are output on author archive pages inside an anchor tag's href attribute. The theme's output function, Fusion_Social_Icon::get_markup(), applies esc_attr() to these values, which escapes HTML metacharacters but does not block dangerous URL schemes such as javascript:. As a result, an attacker who can set these profile fields can embed a javascript: URL that executes when a visitor clicks the resulting social icon link.
Technical Cause
The root cause is insufficient output sanitization: esc_attr() escapes HTML-special characters but does not validate or restrict the URL scheme of attribute values. This is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation, also known as Cross-site Scripting). Because the affected fields are standard WordPress user profile contact methods, any user role capable of editing their own profile fields can supply a malicious javascript: URL in place of a legitimate social media link.
Why It Matters
Exploitation requires an authenticated account with Subscriber-level privileges or higher, which is often the lowest tier of registered users on a WordPress site and may be open to public self-registration on some installations. The attack also requires that a victim click the injected social icon link, and that the site configuration 'Open Social Icons in a New Window' be set to Off; otherwise the javascript: URL would be blocked from opening by the browser. These prerequisites reduce the attack's reach compared to an unauthenticated or zero-click vulnerability, but the CVSS vector reflects a scope change (S:C), meaning the impact can extend beyond the vulnerable component's own security context.
Who Is Affected
Any WordPress site running the Avada theme in versions up to and including 7.16.1 is affected, provided the site allows user registration or otherwise grants Subscriber-level or higher access to untrusted users, and has the 'Open Social Icons in a New Window' setting disabled.
Affected Versions
Avada versions up to and including 7.16.1 are confirmed affected. The fact package references version 7.16.2 as the version where the affected range ends, but the facts available do not explicitly confirm that 7.16.2 contains a fix for this specific issue, and 'fix_available' is marked as false in the source data. Site owners should treat this as unresolved pending further confirmation.
Fixes and Mitigation
The available facts do not confirm that a fix has been released for this vulnerability, despite 7.16.2 being listed as the boundary version in the affected range data. Site administrators should verify directly with the Avada vendor or changelog whether 7.16.2 or a later release addresses this specific stored XSS issue before assuming remediation. As a general precaution, enabling 'Open Social Icons in a New Window' may reduce (but not eliminate) the practical exploitability of this specific attack chain, since it relies on this setting being off.
Recommended Action
Review user registration policies on affected sites to limit who can obtain Subscriber-level accounts. Audit existing user profiles for suspicious or unexpected values in social link contact-method fields. Confirm with the vendor whether a patched version addressing CVE-2026-97340 is available, and apply it once confirmed. In the interim, consider setting 'Open Social Icons in a New Window' to On as a partial mitigation.
PatchBriefing score
4.5 / 10 · Medium
Official CVSS: 6.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Why this score
This vulnerability has a PatchBriefing score of 4.5, reflecting moderate severity. The CVSS base score of 6.4 (AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N) indicates network-exploitable access with low attack complexity, but requires low-privilege authentication and results in low confidentiality and integrity impact with a scope change. The score is moderated by the absence of known exploitation in the wild, no public exploit code, and no EPSS data available. Contributing factors include the requirement for user interaction (a click) despite being marked as 'no_user_interaction: true' in scoring terms, the current lack of a confirmed fix, and the theme's significant install base of approximately 950,000 sites, which increases the pool of potentially exposed installations.
Affected versions
- Avada < 7.16.2
- vulnerable
Reported fixes
The available facts do not confirm that a fix has been released for this vulnerability, despite 7.16.2 being listed as the boundary version in the affected range data. Site administrators should verify directly with the Avada vendor or changelog whether 7.16.2 or a later release addresses this specific stored XSS issue before assuming remediation. As a general precaution, enabling 'Open Social Icons in a New Window' may reduce (but not eliminate) the practical exploitability of this specific attack chain, since it relies on this setting being off.
How this was built
2 source records were collected, matched and used to prepare the report above.
-
WPVulnerability database
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email