+ 19 vulnerabilidades conocidas más
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
CVE-2026-4798
|
Fusion Builder [fusion-builder] < 3.15.2 |
Neutralización incorrecta de elementos especiales en un comando SQL (inyección SQL) |
Alta
7,5
|
< 3.15.2
|
3.15.2 |
2026-05-12 |
⚠ necesita actualización
|
|
CVE-2026-32542
|
Fusion Builder [fusion-builder] < 3.15.0 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Alta
7,1
|
< 3.15.0
|
3.15.0 |
2026-03-20 |
⚠ necesita actualización
|
|
CVE-2026-32452
|
Fusion Builder [fusion-builder] < 3.15.0 |
Falta de control de autorización |
Media
5,3
|
< 3.15.0
|
3.15.0 |
2026-03-10 |
⚠ necesita actualización
|
|
CVE-2026-32451
|
Fusion Builder [fusion-builder] < 3.15.0 |
Falta de control de autorización |
Media
6,5
|
< 3.15.0
|
3.15.0 |
2026-03-10 |
⚠ necesita actualización
|
|
CVE-2026-25472
|
Fusion Builder [fusion-builder] < 3.14.2 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,5
|
< 3.14.2
|
3.14.2 |
2026-01-15 |
⚠ necesita actualización
|
|
CVE-2025-49940
|
Fusion Builder [fusion-builder] < 3.13.3 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,5
|
< 3.13.3
|
3.13.3 |
2025-10-03 |
⚠ necesita actualización
|
|
CVE-2024-13345
|
Fusion Builder [fusion-builder] < 3.11.14 |
Control incorrecto de la generación de código (inyección de código) |
Alta
7,3
|
< 3.11.14
|
3.11.14 |
2025-02-12 |
⚠ necesita actualización
|
|
CVE-2024-12477
|
Fusion Builder [fusion-builder] < 3.11.12 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,4
|
< 3.11.12
|
3.11.12 |
2025-01-22 |
⚠ necesita actualización
|
|
CVE-2024-12335
|
Fusion Builder [fusion-builder] < 3.11.13 |
Elusión de autorización mediante una clave controlada por el usuario |
Media
4,3
|
< 3.11.13
|
3.11.13 |
2024-12-24 |
⚠ necesita actualización
|
|
CVE-2024-5628
|
Fusion Builder [fusion-builder] < 3.11.10 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 3.11.10
|
3.11.10 |
2024-09-12 |
⚠ necesita actualización
|
|
CVE-2023-39311
|
Fusion Builder [fusion-builder] < 3.11.2 |
Falsificación de petición en sitios cruzados (CSRF) |
Alta
7,1
|
< 3.11.2
|
3.11.2 |
2023-08-10 |
⚠ necesita actualización
|
|
CVE-2023-39310
|
Fusion Builder [fusion-builder] < 3.11.2 |
Falta de control de autorización |
Media
5,4
|
< 3.11.2
|
3.11.2 |
2023-08-10 |
⚠ necesita actualización
|
|
CVE-2023-39309
|
Fusion Builder [fusion-builder] < 3.11.2 |
Neutralización incorrecta de elementos especiales en un comando SQL (inyección SQL) |
Alta
8,5
|
< 3.11.2
|
3.11.2 |
2023-08-10 |
⚠ necesita actualización
|
|
CVE-2023-39306
|
Fusion Builder [fusion-builder] < 3.11.2 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Alta
7,1
|
< 3.11.2
|
3.11.2 |
2023-08-10 |
⚠ necesita actualización
|
|
CVE-2022-1386
|
Fusion Builder [fusion-builder] < 3.6.2 |
Falsificación de petición del lado del servidor (SSRF) |
Crítica
9,8
|
< 3.6.2
|
3.6.2 |
2022-04-19 |
⚠ necesita actualización
|
|
CVE-2025-1665
|
Fusion Builder [fusion-builder] < 3.11.15 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 3.11.15
|
3.11.15 |
0000-00-00 |
⚠ necesita actualización
|
|
CVE-2025-6747
|
Fusion Builder [fusion-builder] < 3.12.2 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,4
|
< 3.12.2
|
3.12.2 |
0000-00-00 |
⚠ necesita actualización
|
|
CVE-2026-1541
|
Fusion Builder [fusion-builder] < 3.15.2 |
— |
Media
4,3
|
< 3.15.2
|
3.15.2 |
0000-00-00 |
⚠ necesita actualización
|
|
CVE-2026-1509
|
Fusion Builder [fusion-builder] < 3.15.2 |
— |
Media
5,4
|
< 3.15.2
|
3.15.2 |
0000-00-00 |
⚠ necesita actualización
|
CVE-2026-4798
The Avada Builder plugin for WordPress is vulnerable to time-based SQL Injection via the ‘product_order’ parameter in all versions up to, and including, 3.15.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Note: The vulnerability can only be exploited if WooCommerce was previously used and then deactivated.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2026-32542
The Avada (Fusion) Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to 3.15.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2026-32452
The Avada (Fusion) Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to 3.15.0 (exclusive). This makes it possible for unauthenticated attackers to perform an unauthorized action.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2026-32451
The Avada (Fusion) Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to 3.15.0 (exclusive). This makes it possible for authenticated attackers, with Contributor-level access and above, to perform an unauthorized action.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2026-25472
The Avada (Fusion) Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.14.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2025-49940
The Fusion Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.13.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2024-13345
The Avada Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.11.13. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-12477
The Avada Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 3.11.11 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-12335
The Avada (Fusion) Builder plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.11.12 via the handle_clone_post() function and the 'fusion_blog' shortcode and due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with contributor-level access and above, to extract data from password protected, private, or draft posts that they should not have access to.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-5628
The Avada | Website Builder For WordPress & eCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's fusion_button shortcode in all versions up to, and including, 3.11.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NOTE: This vulnerability was partially fixed in 3.11.9. Additional hardening for alternate attack vectors was added to version 3.11.10.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2023-39311
The Fusion Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.11.1. This is due to missing or incorrect nonce validation on an unknown function. This makes it possible for unauthenticated attackers to modify elements using third-party access tokens via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2023-39310
Update the WordPress Fusion Builder plugin to the latest available version (at least 3.11.2).
Rafie Muhammad (Patchstack) discovered and reported this Broken Access Control vulnerability in WordPress Fusion Builder Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action. This vulnerability has been fixed in version 3.11.2.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2023-39309
The Fusion Builder plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions up to, and including, 3.11.1 due to insufficient escaping on a user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2023-39306
Update the WordPress Fusion Builder plugin to the latest available version (at least 3.11.2).
Rafie Muhammad (Patchstack) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Fusion Builder Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 3.11.2.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2022-1386
The Fusion Builder plugin for WordPress, an Avada theme core plugin, is vulnerable to Server-Side Request Forgery in versions up to 3.6.2 along with the Avada theme in versions up to 7.6.2. This is due to insufficient validation in one of its form parameters. This makes it possible for unauthenticated attackers to interact with internal network hosts via specially crafted requests and can lead to sensitive information disclosure on certain configurations such as AWS.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2025-1665
The Avada (Fusion) Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's shortcodes in all versions up to, and including, 3.11.14 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2025-6747
The Avada (Fusion) Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fusion_map' shortcode in all versions up to, and including, 3.12.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2026-1541
The Avada (Fusion) Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.15.1. This is due to the plugin's `fusion_get_post_custom_field()` function failing to validate whether metadata keys are protected (underscore-prefixed). This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract protected post metadata fields that should not be publicly accessible via the Dynamic Data feature's `post_custom_field` parameter.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2026-1509
The Avada (Fusion) Builder plugin for WordPress is vulnerable to Arbitrary WordPress Action Execution in all versions up to, and including, 3.15.1. This is due to the plugin's `output_action_hook()` function accepting user-controlled input to trigger any registered WordPress action hook without proper authorization checks. This makes it possible for authenticated attackers, with Subscriber-level access and above, to execute arbitrary WordPress action hooks via the Dynamic Data feature, potentially leading to privilege escalation, file inclusion, denial of service, or other security impacts depending on which action hooks are available in the WordPress installation.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Mantén Avada Builder actualizado — 1.55.1 es la última versión en wordpress.org, y cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en").
Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.