Share

We have released Avada 7.16.2, delivering new features, enhancements, improvements, fixes for six security issues, and ongoing security hardening across multiple areas of Avada:

  • SECURITY: FIXED Possible XSS and injection vulnerability in Avada Forms submissions/notification emails.
  • SECURITY: FIXED A possible reflected XSS vulnerability in a legacy theme upgrade routine.
  • SECURITY: FIXED A possible sensitive information exposure in the Instagram Element.
  • SECURITY: FIXED Insufficient validation of checkout data in the Stripe Button Element.
  • SECURITY: FIXED Possible exposure of sensitive information in WooCommerce Order Elements and dynamic data.
  • SECURITY: FIXED Possible Subscriber+ level stored XSS vulnerability via user profile fields.

This is disclosed in our Changelog and our Important Update Info help file.

Like WordPress and any entity that develops software, we understand that security is not absolute and is a continuous process managed as such. We do our best to prevent security issues as proactively as possible, as we do not assume they’ll never come up. Our responsibility is to quickly take care of them and work to get our customers notified and prepared. This is why we recommend keeping your website and plugins up-to-date and maintained at all times.

What Should I Do Next?

We cannot stress enough the importance of ensuring that your website is kept up to date and maintained at all times. Please update to ensure that your installation is issue-free and the fix detailed above is applied. These are our detailed update instructions:

We would like to extend our gratitude and thanks to Wordfence and Patchstack.

Subscribe To Our Newsletter

Receive all of the latest news and updates fresh from ThemeFusion!

Leave a comment