The Avada Fusion Builder plugin for WordPress contains an Arbitrary WordPress Action Execution vulnerability affecting all versions through 3.15.1. The plugin's output_action_hook() function improperly accepts user-controlled input to trigger any registered WordPress action hook without adequate authorization validation, enabling authenticated attackers with Subscriber-level permissions or above to execute arbitrary action hooks through the Dynamic Data feature. Depending on available action hooks in a given installation, this could facilitate privilege escalation, file inclusion, or denial of service attacks. The vulnerability presents a network-accessible attack vector requiring only low complexity and low privilege access (authenticated subscriber account), with a CVSS score of 5.4 indicating medium severity. The exposure carries confidentiality and integrity impacts, though availability is not directly affected by the base vulnerability. Exploitation appears currently limited, with no evidence of active exploitation in the wild according to CISA's Known Exploited Vulnerabilities catalog, and EPSS scoring indicates this CVE ranks below the 3rd percentile for exploitability. Community attention remains minimal, suggesting the security research and threat landscape have not yet elevated this issue to high priority despite its potential for serious impact in vulnerable WordPress installations.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Themefusion | Avada (Fusion) Builder | >= 0, <= 3.15.1CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.