Medium 5.4
2026-04-22< 3.15.2
Avada (Fusion) Builder <= 3.15.1 - Authenticated (Subscriber+) Limited Arbitrary WordPress Action Execution
Minimum safe version
3.15.2
Update to 3.15.2 or later to address 18 fixable vulnerabilities
Avada (Fusion) Builder <= 3.15.1 - Authenticated (Subscriber+) Limited Arbitrary WordPress Action Execution
Avada (Fusion) Builder <= 3.15.1 - Authenticated (Subscriber+) Sensitive Information Exposure via Insecure Direct Object Reference
CVE-2026-32542
CVE-2026-32451
CVE-2026-32452
CVE-2026-25472
CVE-2025-49940
Avada (Fusion) Builder <= 3.12.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Avada Builder <= 3.11.14 - Authenticated (Contributor+) Stored Cross-Site Scripting
CVE-2024-13345
CVE-2024-12477
CVE-2024-12335
CVE-2024-5628
CVE-2023-39306
CVE-2023-39309
CVE-2023-39310
CVE-2023-39311
CVE-2022-1386