Junglewise Threat Intelligence

CVE-2026-1543: ThemeFusion Avada Builder Stored XSS in Shortcodes

CVE-2026-1543 · Severity: medium · CVSS 6.4 · Published 2026-05-21

Technologies: ThemeFusion Avada Builder. Vendors: ThemeFusion.

Executive brief

The Avada (Fusion) Builder plugin for WordPress, a popular tool for designing websites, is vulnerable to a security flaw that allows users with low-level accounts to inject malicious scripts into the site. These scripts are stored on the server and trigger automatically when an administrator views certain pages, such as those displaying user profiles. This could lead to unauthorized actions being performed on behalf of the administrator, potentially compromising the entire website.

Technical details

The Avada (Fusion) Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on multiple shortcodes. An authenticated attacker with Subscriber-level permissions or higher can exploit this by injecting arbitrary web scripts into pages. These scripts are executed in the context of a victim's browser (typically an administrator) when they access a page utilizing the 'Dynamic Data' feature to pull user-supplied information, such as biographical data. This vulnerability is classified under CWE-79 and was addressed in versions following 3.15.2.

Affected products

  • ThemeFusion Avada (Fusion) Builder up to, and including, 3.15.2

Timeline

  • 2026-05-12: patched: Avada version 7.15.3 released (containing updated Fusion Builder)
  • 2026-05-21: disclosed: CVE-2026-1543 published by Wordfence/NVD

References

Related threats