Mmastodon TechnologyCybersecurity first seen 16 h ago, last 16 h ago, peak #6
Critical unauthenticated vulnerability found in BoldThemes Avala plugin
Original: ๐จ EUVD-2026-96489 ๐ Score: 9.8/10 (CVSS v3.1) ๐ฆ Product: Avala ๐ข Vendor: boldthemes ๐ Updated: 2026-10-10 ๐ Unauthentica
A critical vulnerability, EUVD-2026-96489, has been catalogued affecting Avala, a product by vendor BoldThemes. The flaw is rated 9.8 out of 10 on the CVSS v3.1 scale and involves unauthenticated PHP object injection, meaning attackers would not need credentials to exploit it. It was updated in the EU vulnerability database on 10 October 2026. Administrators running Avala are being urged to review the advisory and patch promptly.
Why now: A maximum-severity, unauthenticated flaw in a widely used theme vendor's product demands immediate attention from site administrators.
BoldThemesAvalaENISAEUVD-2026-96489
Rank over time, top of the chart is #1. 2 snapshots from 16 h ago to 16 h ago.
Evidence
API: https://socialmediatrends-api.osmike.com/v1/trends/1777493