These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
The Avada (Fusion) Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Module Title’ parameter in all versions up to, and including, 3.15.5. This vulnerability is due to insufficient input sanitization and output escaping, making it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenev [truncated]
CVE-2026-56008 is a high-severity vulnerability in Fusion Builder plugin versions <= 3.15.4. It allows contributors to escalate their privileges. The vulnerability has a CVSS score of 8.8 and is considered HIGH. The CVE was published on 2026-06-26T15:16:41.927Z and last modified on 2026-06-29T16:16:41.930Z. Evidence from Patchstack suggests that the vulnerability exists. However, details about the vendor [truncated]
The CVE-2026-54193 vulnerability is a contributor arbitrary file deletion issue in Fusion Builder plugin versions <= 3.15.4. The vulnerability has a CVSS score of 7.7 and a HIGH severity. The CVE record was published on 2026-06-17T14:17:58.383Z and has not been modified since then. Users of Fusion Builder plugin versions <= 3.15.4 should review and apply patches from the vendor. The vulnerability allows c [truncated]
A critical vulnerability, CVE-2026-54194, has been discovered in Fusion Builder versions up to 3.15.4. This vulnerability allows unauthenticated attackers to inject malicious PHP objects, potentially leading to arbitrary code execution. With a CVSS score of 9.8, this vulnerability is considered critical and requires immediate attention. The vulnerability was published on June 17, 2026, and has since been [truncated]
A high-severity vulnerability was found in Avada, a theme for WordPress, which could allow an attacker to inject malicious PHP objects. This issue, tracked as CVE-2026-12256, has a CVSS score of 8.8 and was publicly disclosed on 2026-06-17. The vulnerability is caused by a PHP object injection issue in the Avada theme, allowing an attacker with contributor-level access to potentially inject malicious PHP [truncated]
CVE-2026-6279 describes a critical unauthenticated remote code execution issue in the Avada Builder (fusion-builder) WordPress plugin. The core problem is attacker-controlled data being passed from a base64-decoded JSON blob into call_user_func() without allowlist validation in the wp_conditional_tags path. Because the vulnerable logic is reachable through the non-privileged fusion_get_widget_markup AJAX [truncated]
CVE-2026-1543 is a stored cross-site scripting issue in the Avada (Fusion) Builder plugin for WordPress. According to the supplied source, multiple shortcodes fail to properly sanitize input and escape output in versions up to and including 3.15.2. That allows authenticated users with Subscriber-level access and above to store arbitrary scripts that can execute when another user views a page rendering the [truncated]