Sensitive Information Exposure in Avada Builder Plugin for WordPress
CVE-2026-1541

4.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
15 April 2026

What is CVE-2026-1541?

The Avada (Fusion) Builder plugin for WordPress is susceptible to a sensitive information exposure flaw in versions up to 3.15.1. This vulnerability arises from the failure of the fusion_get_post_custom_field() function to validate the metadata keys that should be protected, specifically those prefixed with an underscore. As a result, authenticated users with Subscriber-level access or higher can access and extract sensitive post metadata fields via the Dynamic Data feature's post_custom_field parameter, which should otherwise be restricted from public exposure. Website administrators are advised to update to a patched version of the plugin to mitigate this risk.

Affected Version(s)

Avada (Fusion) Builder 0 <= 3.15.1

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Craig Smith
.