Executive brief
The Avada (Fusion) Builder plugin, a popular website-building tool for WordPress, contains a security flaw that allows users with basic contributor access to inject malicious scripts into website pages. When other users, including site administrators or visitors, view these compromised pages, the hidden scripts will execute automatically in their browsers. This could lead to unauthorized actions being performed on behalf of other users or the theft of sensitive session information.
Technical details
A Stored Cross-Site Scripting (XSS) vulnerability exists in the Avada (Fusion) Builder plugin for WordPress due to inadequate sanitization and escaping of the 'Module Title' parameter. Authenticated attackers with Contributor-level permissions or higher can inject arbitrary JavaScript into this parameter. Because the input is stored in the database and rendered without proper security controls, the script executes in the context of any user who views the affected page. This vulnerability is tracked as CVE-2026-12536 and affects all versions up to 3.15.5.
Affected products
- ThemeFusion Avada (Fusion) Builder up to, and including, 3.15.5
Timeline
- 2026-07-13: disclosed
- 2026-07-13: advisory