WordPress security by component
Fusion Builder
Plugin description
Fusion Builder is a WordPress component with 15 published CVE records in this archive. The latest tracked vulnerability was published Jun 26, 2026; the highest CVE/CNA score is 9.8.
Plugin slug:
fusion-builderLatest vulnerability
CVE-2026-56008: Fusion Builder: Privilege escalation or authentication bypass
Fusion Builder is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess. The published affected range is n/a through 3.15.4.
| Safe version |
|
||
|---|---|---|---|
| Jun 26, 2026 |
CVE-2026-56008
Fusion Builder: Privilege escalation or authentication bypass
Fusion Builder is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess. The published affected range is n/a through 3.15.4.
|
3.15.5 |
CVE8.8
NVDPending
|
| Jun 19, 2026 |
CVE-2026-8713
Avada (Fusion) Builder: Code execution
Avada (Fusion) Builder is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is <= 3.15.3.
|
> 3.15.3 |
CVE9.1
NVDPending
|
| Jun 17, 2026 |
CVE-2026-54193
Fusion Builder: Arbitrary file deletion
Fusion Builder is affected by arbitrary file deletion. Exposure depends on how the affected operation is made reachable by the site. A successful request can remove files outside the intended scope and may make the site unavailable. The published affected range is n/a through 3.15.4.
|
3.15.5 |
CVE7.7
NVDPending
|
| Jun 17, 2026 |
CVE-2026-54194
Fusion Builder: Code execution
Fusion Builder is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is n/a through 3.15.4.
|
3.15.5 |
CVE9.8
NVDPending
|
| May 21, 2026 |
CVE-2026-6279
Avada (Fusion) Builder: Code execution
Avada (Fusion) Builder is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is <= 3.15.2.
|
> 3.15.2 |
CVE9.8
NVDPending
|
| Mar 25, 2026 |
CVE-2026-32542
Fusion Builder: Cross-site scripting
Fusion Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through < 3.15.0.
|
3.15.0 |
CVE7.1
NVDPending
|
| Mar 13, 2026 |
CVE-2026-32452
Fusion Builder: A security weakness
Fusion Builder is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Mar 13, 2026 |
CVE-2026-32451
Fusion Builder: A security weakness
Fusion Builder is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Feb 19, 2026 |
CVE-2026-25472
Fusion Builder: Cross-site scripting
Fusion Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Oct 22, 2025 |
CVE-2025-49940
Fusion Builder: Cross-site scripting
Fusion Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Jun 19, 2024 |
CVE-2023-39310
Fusion Builder: A security weakness
Fusion Builder is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.4
NVDPending
|
| Mar 28, 2024 |
CVE-2023-39309
Fusion Builder: SQL injection
Fusion Builder is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE8.5
NVD8.8
|
| Mar 27, 2024 |
CVE-2023-39311
Fusion Builder: Cross-site request forgery
Fusion Builder is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE7.1
NVD8.8
|
| Mar 27, 2024 |
CVE-2023-39306
Fusion Builder: Cross-site scripting
Fusion Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVDPending
|
| May 16, 2022 |
CVE-2022-1386
Fusion Builder: A security weakness
Fusion Builder is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE9.8
NVD9.8
|