PatchSiren cyber security CVE debrief
CVE-2026-97670 themefusion CVE debrief
The Avada (Fusion) Builder plugin for WordPress has a critical vulnerability allowing unauthenticated arbitrary WordPress action invocation. This could lead to permanent destruction of site content, denial of service, and potentially further privileged writes if vulnerable third-party handlers are installed. The vulnerability exists due to improper authorization verification before dispatching a WordPress action hook from an attacker-supplied form-field value.
- Vendor
- themefusion
- Product
- Avada (Fusion) Builder
- CVSS
- CRITICAL 9.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-10
- Original CVE updated
- 2026-10-10
- Advisory published
- 2026-10-10
- Advisory updated
- 2026-10-10
Who should care
WordPress administrators and users of the Avada (Fusion) Builder plugin should assess their exposure and take immediate action to update the plugin and restrict usage of WordPress action hooks.
Why it matters
CVE-2026-97670 allows unauthenticated attackers to invoke arbitrary WordPress action hooks in the Avada (Fusion) Builder plugin, potentially leading to significant site disruptions and security risks. Immediate assessment and remediation are crucial for WordPress administrators and users of the affected plugin.
- Potential permanent destruction of site content via arbitrary WordPress action invocation
- Denial of service through invocation of certain action hooks
- Potential for further privileged writes if vulnerable third-party handlers are installed
- Need for verification of affected versions and remediation efforts
Technical summary
The Avada (Fusion) Builder plugin for WordPress is vulnerable to authorization bypass due to improper verification of authorization before dispatching a WordPress action hook. This allows unauthenticated attackers to invoke arbitrary WordPress action hooks, potentially leading to permanent destruction of site content, denial of service, and further privileged writes if vulnerable third-party handlers are installed. The vulnerability exists due to the plugin not properly verifying authorization before dispatching a WordPress action hook whose name is taken from an attacker-supplied form-field value.
Defensive priority
High priority for immediate assessment and remediation
Recommended defensive actions
- Immediately assess and update Avada (Fusion) Builder to version 7.16.2 or later
- Review and restrict usage of WordPress action hooks
- Monitor for suspicious activity and potential exploitation attempts
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The vulnerability was verified through a supplied CVE record and source item details. However, specific details about exploitation or victim impact are limited. Affected product deployments should be confirmed in managed environments, and owners should be assigned for follow-up. The official advisory or CVE record should be reviewed to validate affected scope, severity, and vendor guidance. Defenders should verify the existence of affected versions and perform remediation efforts.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-97670 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-97670
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-97670 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-97670
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Avada (Fusion) Builder <= 7.16.1 - Unauthenticated Arbitrary WordPress Action Invocation via '{a
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/97xxx/CVE-2026-97670.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://avada.com/blog/version-7-16-2-security-update/
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.