Junglewise Threat Intelligence

CVE-2026-4782: Avada Builder arbitrary file read in fusion_get_svg_from_file

CVE-2026-4782 · Severity: medium · CVSS 6.5 · Published 2026-05-13

Technologies: ThemeFusion Avada Builder. Vendors: ThemeFusion.

Executive brief

Avada Builder, a popular page-building tool for WordPress websites, contains a security flaw that allows logged-in users to view private files on the web server. Even users with low-level access, such as subscribers, could exploit this to steal sensitive configuration data or system information. This could lead to further attacks or the exposure of confidential site data.

Technical details

The Avada Builder plugin for WordPress is vulnerable to an arbitrary file read vulnerability (path traversal) due to insufficient input validation in the 'fusion_get_svg_from_file' function. Specifically, the 'custom_svg' parameter within the 'fusion_section_separator' shortcode does not properly sanitize file paths. An authenticated attacker with Subscriber-level permissions or higher can exploit this to retrieve the contents of arbitrary files on the server, such as wp-config.php. The issue was partially addressed in version 3.15.2 and fully resolved in version 3.15.3.

Affected products

  • ThemeFusion Avada Builder up to and including 3.15.2

Timeline

  • 2026-05-13: disclosed
  • 2026-05-13: advisory
  • 2026-05-13: patched: Full patch released in version 3.15.3

References

Related threats