Junglewise Threat Intelligence

CVE-2026-56008: ThemeFusion Fusion Builder privilege escalation in WordPress plugin

CVE-2026-56008 · Severity: high · CVSS 8.8 · Published 2026-06-26

Technologies: ThemeFusion Fusion Builder. Vendors: ThemeFusion.

Executive brief

Fusion Builder, a popular page-building tool for WordPress websites, contains a security flaw that allows users with low-level 'Contributor' accounts to gain unauthorized administrative privileges. If exploited, an attacker could take full control of the website, potentially leading to data theft, site defacement, or the installation of malicious software. This vulnerability is considered high risk because it can be used to compromise a site's entire operations starting from a standard user account.

Technical details

A privilege escalation vulnerability exists in the ThemeFusion Fusion Builder plugin for WordPress (versions 3.15.4 and earlier) due to incorrect privilege assignment (CWE-266). An authenticated attacker with 'Contributor' level permissions can exploit this flaw over the network without user interaction to escalate their privileges, potentially gaining full administrative control over the WordPress instance. The vulnerability has been addressed in version 3.15.5. The CVSS 3.1 base score is 8.8, reflecting high impact on confidentiality, integrity, and availability.

Affected products

  • ThemeFusion Fusion Builder <= 3.15.4

Timeline

  • 2026-05-13: disclosed: Reported by researcher daroo
  • 2026-06-18: advisory: Patchstack published advisory
  • 2026-06-26: patched: NVD published date; fix available in version 3.15.5

References

Related threats