Junglewise Threat Intelligence

CVE-2026-54193: ThemeFusion Fusion Builder arbitrary file deletion via path traversal

CVE-2026-54193 · Severity: high · CVSS 7.7 · Published 2026-06-17

Technologies: ThemeFusion Fusion Builder. Vendors: ThemeFusion.

Executive brief

Fusion Builder, a popular page-building tool for WordPress websites, contains a security flaw that allows users with 'Contributor' level access to delete arbitrary files on the server. This could lead to a complete website outage if critical system files are removed, or it could be used to bypass security controls by deleting configuration files. The vulnerability is particularly concerning for sites that allow multiple users to contribute content.

Technical details

A path traversal vulnerability (CWE-22) exists in the Fusion Builder plugin for WordPress up to version 3.15.4. The flaw allows authenticated attackers with Contributor-level roles to delete arbitrary files on the server by manipulating file paths. This is achieved through insufficient validation of user-supplied input in file-handling components. Successful exploitation can lead to a denial-of-service (DoS) condition by deleting core WordPress or plugin files. The issue is resolved in version 3.15.5.

Affected products

  • ThemeFusion Fusion Builder <= 3.15.4

Timeline

  • 2026-06-10: other: Reported by researcher daroo
  • 2026-06-16: advisory: Patchstack advisory published
  • 2026-06-17: disclosed: NVD publication date
  • 2026-06-17: patched: Version 3.15.5 released to address the vulnerability

References

Related threats