Executive brief
Avada (Fusion) Builder is a popular WordPress page builder plugin used to create website layouts and content. The plugin fails to properly sanitize user input in shortcode attributes, allowing authenticated users with contributor-level access to inject malicious scripts that execute whenever anyone visits the affected pages. This could lead to unauthorized actions, data theft, or website defacement.
Technical details
The vulnerability is a stored cross-site scripting (XSS) flaw in the 'size' shortcode attribute of the Avada plugin that affects all versions up to and including 3.15.6. The root cause is insufficient input sanitization and output escaping; WordPress's wp_kses_post filter does not strip the payload because it resides entirely within a shortcode attribute string containing no HTML angle brackets, allowing the malicious content to persist at save time. An authenticated attacker with contributor-level access or above can inject arbitrary JavaScript that executes in the browser of any user viewing the affected page. A patch is expected in version 3.15.7 or later.
Affected products
- ThemeFusion Avada (Fusion) Builder up to 3.15.6
Timeline
- 2026-08-28: disclosed
- other: Latest Avada version 7.16.1 released 2026-08-25