Cross-Site Scripting Vulnerability in Avada Core by ThemeFusion
CVE-2026-32454
6.5MEDIUM
What is CVE-2026-32454?
The Avada Core plugin developed by ThemeFusion contains a vulnerability that allows attackers to execute arbitrary scripts in the browser of a user visiting the affected web page. This improper neutralization of input during web page generation leads to DOM-based Cross-Site Scripting (XSS) attacks, exposing users to potential data theft or manipulation. The issue affects all versions of Avada Core prior to 5.15.0, necessitating immediate patching for users to safeguard their websites.
Affected Version(s)
Avada Core 0 <= 5.15.0