Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-1509

19
FAUCET Score

The Avada Fusion Builder plugin for WordPress contains an Arbitrary WordPress Action Execution vulnerability affecting all versions through 3.15.1. The plugin's output_action_hook() function improperly accepts user-controlled input to trigger any registered WordPress action hook without adequate authorization validation, enabling authenticated attackers with Subscriber-level permissions or above to execute arbitrary action hooks through the Dynamic Data feature. Depending on available action hooks in a given installation, this could facilitate privilege escalation, file inclusion, or denial of service attacks. The vulnerability presents a network-accessible attack vector requiring only low complexity and low privilege access (authenticated subscriber account), with a CVSS score of 5.4 indicating medium severity. The exposure carries confidentiality and integrity impacts, though availability is not directly affected by the base vulnerability. Exploitation appears currently limited, with no evidence of active exploitation in the wild according to CISA's Known Exploited Vulnerabilities catalog, and EPSS scoring indicates this CVE ranks below the 3rd percentile for exploitability. Community attention remains minimal, suggesting the security research and threat landscape have not yet elevated this issue to high priority despite its potential for serious impact in vulnerable WordPress installations.

Impacted Technologies

VendorProductVersion(s)CPE
ThemefusionAvada (Fusion) Builder
>= 0, <= 3.15.1CNA affecteddefault unaffected

CVSS Data

CVSS version used by this source: 3.1

5.4MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
2.5
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.31%
Probability of exploitation in next 30 days
EPSS Percentile
23.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0031 is in the 30th percentile among its peer group of 21,977 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

avada.com / documentation/avada-changelog
themeforest.net / item/avada-responsive-multipurpose-theme/2833226
wordfence.com / threat-intel/vulnerabilities/id/fdc57b06-bae9-49a3-84dd-f593705330e9