Stored Cross-Site Scripting Vulnerability in Avada Builder Plugin for WordPress
CVE-2026-1543
6.4MEDIUM
What is CVE-2026-1543?
The Avada (Fusion) Builder plugin for WordPress presents a Stored Cross-Site Scripting flaw due to inadequate input sanitization and output escaping. This vulnerability impacts all versions up to 3.15.2, allowing authenticated attackers with Subscriber-level access or higher to exploit it. They can inject arbitrary web scripts into the site's pages, which can execute in the browser of any user who views dynamic user data, such as administrator accounts. Proper handling and validation of user input are essential to mitigate the risks associated with this vulnerability.
Affected Version(s)
Avada (Fusion) Builder 0 <= 3.15.2