PatchSiren

themefusion CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM themefusion CVE published 2026-07-13

CVE-2026-12536

The Avada (Fusion) Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Module Title’ parameter in all versions up to, and including, 3.15.5. This vulnerability is due to insufficient input sanitization and output escaping, making it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenev [truncated]

HIGH ThemeFusion CVE published 2026-06-26

CVE-2026-56008

CVE-2026-56008 is a high-severity vulnerability in Fusion Builder plugin versions <= 3.15.4. It allows contributors to escalate their privileges. The vulnerability has a CVSS score of 8.8 and is considered HIGH. The CVE was published on 2026-06-26T15:16:41.927Z and last modified on 2026-06-29T16:16:41.930Z. Evidence from Patchstack suggests that the vulnerability exists. However, details about the vendor [truncated]

HIGH ThemeFusion CVE published 2026-06-17

CVE-2026-54193

The CVE-2026-54193 vulnerability is a contributor arbitrary file deletion issue in Fusion Builder plugin versions <= 3.15.4. The vulnerability has a CVSS score of 7.7 and a HIGH severity. The CVE record was published on 2026-06-17T14:17:58.383Z and has not been modified since then. Users of Fusion Builder plugin versions <= 3.15.4 should review and apply patches from the vendor. The vulnerability allows c [truncated]

CRITICAL ThemeFusion CVE published 2026-06-17

CVE-2026-54194

A critical vulnerability, CVE-2026-54194, has been discovered in Fusion Builder versions up to 3.15.4. This vulnerability allows unauthenticated attackers to inject malicious PHP objects, potentially leading to arbitrary code execution. With a CVSS score of 9.8, this vulnerability is considered critical and requires immediate attention. The vulnerability was published on June 17, 2026, and has since been [truncated]

HIGH ThemeFusion CVE published 2026-06-17

CVE-2026-12256

A high-severity vulnerability was found in Avada, a theme for WordPress, which could allow an attacker to inject malicious PHP objects. This issue, tracked as CVE-2026-12256, has a CVSS score of 8.8 and was publicly disclosed on 2026-06-17. The vulnerability is caused by a PHP object injection issue in the Avada theme, allowing an attacker with contributor-level access to potentially inject malicious PHP [truncated]

CRITICAL themefusion CVE published 2026-05-21

CVE-2026-6279

CVE-2026-6279 describes a critical unauthenticated remote code execution issue in the Avada Builder (fusion-builder) WordPress plugin. The core problem is attacker-controlled data being passed from a base64-decoded JSON blob into call_user_func() without allowlist validation in the wp_conditional_tags path. Because the vulnerable logic is reachable through the non-privileged fusion_get_widget_markup AJAX [truncated]

MEDIUM themefusion CVE published 2026-05-21

CVE-2026-1543

CVE-2026-1543 is a stored cross-site scripting issue in the Avada (Fusion) Builder plugin for WordPress. According to the supplied source, multiple shortcodes fail to properly sanitize input and escape output in versions up to and including 3.15.2. That allows authenticated users with Subscriber-level access and above to store arbitrary scripts that can execute when another user views a page rendering the [truncated]