Executive brief
Fusion Builder, a popular page-building tool for WordPress websites, contains a critical security flaw. This vulnerability allows an attacker to inject malicious data that the website then processes as code. If exploited, this could lead to a total takeover of the website, including the theft of sensitive data, site defacement, or the installation of malware.
Technical details
A PHP Object Injection vulnerability exists in ThemeFusion Fusion Builder (versions <= 3.15.4) due to the deserialization of untrusted data (CWE-502). While the advisory title mentions 'Contributor' level, the CVSS vector (PR:N) and CISA metadata suggest the flaw may be automatable and potentially reachable without high privileges. If a suitable Property-Oriented Programming (POP) chain is present on the server, an attacker can leverage this to achieve remote code execution, SQL injection, or arbitrary file access. The issue is resolved in version 3.15.5.
Affected products
- ThemeFusion Fusion Builder <= 3.15.4
Timeline
- 2026-06-10: other: Reported by researcher daroo
- 2026-06-15: disclosed: Vulnerability disclosed by Patchstack
- 2026-06-17: advisory: NVD published date