MikeTrendsTrends right now

Mmastodon TechnologyCybersecurity first seen 12 h ago, last 12 h ago, peak #6

Critical unauthenticated vulnerability found in BoldThemes Avala plugin

Original: ๐Ÿšจ EUVD-2026-96489 ๐Ÿ“Š Score: 9.8/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Avala ๐Ÿข Vendor: boldthemes ๐Ÿ“… Updated: 2026-10-10 ๐Ÿ“ Unauthentica

A critical vulnerability, EUVD-2026-96489, has been catalogued affecting Avala, a product by vendor BoldThemes. The flaw is rated 9.8 out of 10 on the CVSS v3.1 scale and involves unauthenticated PHP object injection, meaning attackers would not need credentials to exploit it. It was updated in the EU vulnerability database on 10 October 2026. Administrators running Avala are being urged to review the advisory and patch promptly.

Why now: A maximum-severity, unauthenticated flaw in a widely used theme vendor's product demands immediate attention from site administrators.

BoldThemesAvalaENISAEUVD-2026-96489

Open on mastodon โ†’

Rank over time, top of the chart is #1. 2 snapshots from 12 h ago to 12 h ago.

Evidence

API: https://socialmediatrends-api.osmike.com/v1/trends/1777493