Sensitive Information Exposure in Avada Builder Plugin for WordPress
CVE-2026-1541
4.3MEDIUM
What is CVE-2026-1541?
The Avada (Fusion) Builder plugin for WordPress is susceptible to a sensitive information exposure flaw in versions up to 3.15.1. This vulnerability arises from the failure of the fusion_get_post_custom_field() function to validate the metadata keys that should be protected, specifically those prefixed with an underscore. As a result, authenticated users with Subscriber-level access or higher can access and extract sensitive post metadata fields via the Dynamic Data feature's post_custom_field parameter, which should otherwise be restricted from public exposure. Website administrators are advised to update to a patched version of the plugin to mitigate this risk.
Affected Version(s)
Avada (Fusion) Builder 0 <= 3.15.1