PT-2026-81951 · WordPress+1 · Fusion Builder+1
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Avada versions prior to 7.16.1
Fusion Builder versions prior to 3.16.1
Description
An unauthenticated attacker can achieve remote code execution and complete site compromise by writing attacker-controlled PHP files to the server. This is possible through a six-stage chain of weaknesses involving authorization, input validation, trust boundaries, privileged behavior, and file handling across the theme and its required plugin. Successful exploitation requires both the theme and the plugin to be installed and active, as well as the presence of certain administrator-authored content. Over 1 million sites are potentially affected.
Recommendations
Update Avada to version 7.16.1 or later.
Update Fusion Builder to version 3.16.1 or later.
Fix
RCE
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Avada
Fusion Builder