Junglewise Threat Intelligence

CVE-2026-65524: ThemeFusion Avada Custom Branding broken access control

CVE-2026-65524 · Severity: medium · CVSS 4.3 · Published 2026-07-23

Vendors: ThemeFusion.

Executive brief

Avada Custom Branding is a WordPress plugin used to customize and rebrand the WordPress dashboard for clients. A security flaw allows users with 'Contributor' level access—who should normally only be able to write posts—to bypass security checks and perform actions they are not authorized to do. This could lead to unauthorized changes to the site's branding or administrative settings.

Technical details

The Avada Custom Branding plugin (also known as Fusion White Label Branding) for WordPress is vulnerable to broken access control due to missing authorization checks (CWE-862). An attacker with a minimum of Contributor-level privileges can exploit this flaw over the network without user interaction. This allows the attacker to execute functions or access data that should be restricted to higher-privileged users, such as administrators. As of the advisory date, no official patch has been released for versions 1.2 and below.

Affected products

  • ThemeFusion Avada Custom Branding (Fusion White Label Branding) <= 1.2

Timeline

  • 2026-02-08: other: Reported by researcher Bonds
  • 2026-07-23: disclosed: Public disclosure via Patchstack and NVD

References