Executive brief
Avada Core is a foundational component for the popular Avada WordPress theme, used to manage site layouts and core functionality. A security flaw allows an attacker to trick a site administrator into performing unintended actions, such as changing site settings or creating new administrative accounts, by clicking a malicious link. This could lead to a full takeover of the website and loss of control over its content and data.
Technical details
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Avada Core (formerly Fusion Core) plugin for WordPress due to insufficient validation of request origins or missing nonce tokens. An unauthenticated remote attacker can craft a malicious web page or link that, when visited by a logged-in administrator, forces the victim's browser to execute administrative actions without their consent. Given the 'Critical' CVSS score and 'Scope: Changed' (S:C) metric, this likely allows for significant state-changing operations such as privilege escalation or site configuration changes. The vulnerability is addressed in version 5.15.7.
Affected products
- ThemeFusion Avada Core (Fusion Core) <= 5.15.6
Timeline
- 2026-07-13: other: Reported by Luis Koleski
- 2026-07-22: advisory: Patchstack advisory published
- 2026-07-23: disclosed: NVD publication date
- 2026-07-22: patched: Fixed in version 5.15.7