Cross-Site Scripting Vulnerability in Avada Core by ThemeFusion
CVE-2026-32454

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
13 March 2026

What is CVE-2026-32454?

The Avada Core plugin developed by ThemeFusion contains a vulnerability that allows attackers to execute arbitrary scripts in the browser of a user visiting the affected web page. This improper neutralization of input during web page generation leads to DOM-based Cross-Site Scripting (XSS) attacks, exposing users to potential data theft or manipulation. The issue affects all versions of Avada Core prior to 5.15.0, necessitating immediate patching for users to safeguard their websites.

Affected Version(s)

Avada Core 0 <= 5.15.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Bonds | Patchstack Bug Bounty Program
.