Skip to content

[GHSA-f53p-382v-8pj7] The Avada Builder (fusion-builder) plugin for WordPress...#8019

Open
vanesabravon wants to merge 1 commit into
vanesabravon/advisory-improvement-8019from
vanesabravon-GHSA-f53p-382v-8pj7
Open

[GHSA-f53p-382v-8pj7] The Avada Builder (fusion-builder) plugin for WordPress...#8019
vanesabravon wants to merge 1 commit into
vanesabravon/advisory-improvement-8019from
vanesabravon-GHSA-f53p-382v-8pj7

Conversation

@vanesabravon

Copy link
Copy Markdown

Updates

  • Affected products
  • Description
  • Summary

Comments
The published CVE states that the fusion_load_nonce nonce is exposed only through [fusion_post_cards] or [fusion_table_of_contents] shortcodes. Forensic analysis of an active exploitation confirms that the nonce is also exposed via the fb-edit=1 frontend editing parameter, which is enabled by default and available on any public URL of any Avada Builder installation. This means all installations up to 3.15.2 are universally vulnerable regardless of page configuration or shortcodes in use, significantly broader than the current CVE description implies.

Copilot stopped work on behalf of vanesabravon due to an error June 12, 2026 08:31
@github-actions github-actions Bot changed the base branch from main to vanesabravon/advisory-improvement-8019 June 12, 2026 08:32
@JonathanLEvans

Copy link
Copy Markdown

Hi @vanesabravon,

If that is the case then you should contact the assigning CNA (cve-request@wordfence.com). They may update the CVE description or possibly assign a new CVE ID.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants