CVE Database /
CVE-2026-32451
CVE · Medium
CVE-2026-32451 — Fusion Builder [fusion-builder] < 3.15.0
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-32451
|
Fusion Builder [fusion-builder] < 3.15.0 |
Missing Authorization |
Medium
6.5
|
< 3.15.0
|
3.15.0 |
2026-03-10 |
—
|
CVE-2026-32451
A security flaw exists within the Avada Builder plugin for WordPress, specifically affecting versions prior to 3.15.1. The issue stems from a lack of capability verification in certain plugin functions, enabling users with contributor privileges or higher to execute unauthorized actions without proper authorization. This vulnerability affects all plugin iterations up to and excluding version 3.15.0.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings