Stored Cross-Site Scripting Vulnerability in Avada Builder Plugin for WordPress
CVE-2026-1543

6.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
21 May 2026

What is CVE-2026-1543?

The Avada (Fusion) Builder plugin for WordPress presents a Stored Cross-Site Scripting flaw due to inadequate input sanitization and output escaping. This vulnerability impacts all versions up to 3.15.2, allowing authenticated attackers with Subscriber-level access or higher to exploit it. They can inject arbitrary web scripts into the site's pages, which can execute in the browser of any user who views dynamic user data, such as administrator accounts. Proper handling and validation of user input are essential to mitigate the risks associated with this vulnerability.

Affected Version(s)

Avada (Fusion) Builder 0 <= 3.15.2

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Craig Smith
.