Arbitrary File Read Vulnerability in Avada Builder for WordPress
CVE-2026-4782

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
13 May 2026

What is CVE-2026-4782?

The Avada Builder plugin for WordPress has a vulnerability that allows authenticated users with Subscriber-level access and higher to read arbitrary files from the server using the 'custom_svg' parameter in the 'fusion_get_svg_from_file' function of the 'fusion_section_separator' shortcode. Versions up to 3.15.2 are affected, allowing potential exposure of sensitive information stored on the server. While the vulnerability was partially addressed in version 3.15.2, a full patch was implemented in version 3.15.3, emphasizing the importance of keeping the plugin updated.

Affected Version(s)

Avada (Fusion) Builder 0 <= 3.15.2

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rafie Muhammad
.