PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-97670 themefusion CVE debrief

The Avada (Fusion) Builder plugin for WordPress has a critical vulnerability allowing unauthenticated arbitrary WordPress action invocation. This could lead to permanent destruction of site content, denial of service, and potentially further privileged writes if vulnerable third-party handlers are installed. The vulnerability exists due to improper authorization verification before dispatching a WordPress action hook from an attacker-supplied form-field value.

Vendor
themefusion
Product
Avada (Fusion) Builder
CVSS
CRITICAL 9.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-10
Original CVE updated
2026-10-10
Advisory published
2026-10-10
Advisory updated
2026-10-10

Who should care

WordPress administrators and users of the Avada (Fusion) Builder plugin should assess their exposure and take immediate action to update the plugin and restrict usage of WordPress action hooks.

Why it matters

CVE-2026-97670 allows unauthenticated attackers to invoke arbitrary WordPress action hooks in the Avada (Fusion) Builder plugin, potentially leading to significant site disruptions and security risks. Immediate assessment and remediation are crucial for WordPress administrators and users of the affected plugin.

  • Potential permanent destruction of site content via arbitrary WordPress action invocation
  • Denial of service through invocation of certain action hooks
  • Potential for further privileged writes if vulnerable third-party handlers are installed
  • Need for verification of affected versions and remediation efforts

Technical summary

The Avada (Fusion) Builder plugin for WordPress is vulnerable to authorization bypass due to improper verification of authorization before dispatching a WordPress action hook. This allows unauthenticated attackers to invoke arbitrary WordPress action hooks, potentially leading to permanent destruction of site content, denial of service, and further privileged writes if vulnerable third-party handlers are installed. The vulnerability exists due to the plugin not properly verifying authorization before dispatching a WordPress action hook whose name is taken from an attacker-supplied form-field value.

Defensive priority

High priority for immediate assessment and remediation

Recommended defensive actions

  • Immediately assess and update Avada (Fusion) Builder to version 7.16.2 or later
  • Review and restrict usage of WordPress action hooks
  • Monitor for suspicious activity and potential exploitation attempts
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The vulnerability was verified through a supplied CVE record and source item details. However, specific details about exploitation or victim impact are limited. Affected product deployments should be confirmed in managed environments, and owners should be assigned for follow-up. The official advisory or CVE record should be reviewed to validate affected scope, severity, and vendor guidance. Defenders should verify the existence of affected versions and perform remediation efforts.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-97670 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-97670

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-97670 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-97670

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.