Executive brief
The Avante theme for WordPress is vulnerable to a security flaw that allows attackers to inject malicious scripts into the website. This occurs when a user clicks on a specially crafted link, potentially leading to unauthorized actions performed in the user's browser, such as data theft or website redirection. Business operations may be impacted by damaged reputation or the distribution of malware to site visitors.
Technical details
A reflected Cross-Site Scripting (XSS) vulnerability exists in the ThemeGoods Avante theme for WordPress due to improper neutralization of user-supplied input during web page generation (CWE-79). An unauthenticated remote attacker can exploit this by tricking a user into clicking a malicious link or visiting a crafted URL. Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's browser session, which can lead to session hijacking or unauthorized administrative actions if the victim is an authenticated administrator. The issue is resolved in version 3.0.5.
Affected products
- ThemeGoods Avante < 3.0.5
Timeline
- 2025-11-06: other: Vulnerability reported by researcher Kinorth
- 2026-05-08: disclosed: Initial disclosure by Patchstack
- 2026-06-17: advisory: NVD publication date
- 2026-06-17: patched: Patch confirmed available in version 3.0.5