Arbitrary File Read Vulnerability in Avada Builder for WordPress
CVE-2026-4782
6.5MEDIUM
What is CVE-2026-4782?
The Avada Builder plugin for WordPress has a vulnerability that allows authenticated users with Subscriber-level access and higher to read arbitrary files from the server using the 'custom_svg' parameter in the 'fusion_get_svg_from_file' function of the 'fusion_section_separator' shortcode. Versions up to 3.15.2 are affected, allowing potential exposure of sensitive information stored on the server. While the vulnerability was partially addressed in version 3.15.2, a full patch was implemented in version 3.15.3, emphasizing the importance of keeping the plugin updated.
Affected Version(s)
Avada (Fusion) Builder 0 <= 3.15.2