CVE Database /
CVE-2026-4798
CVE · High
CVE-2026-4798 — Fusion Builder [fusion-builder] < 3.15.2
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-4798
|
Fusion Builder [fusion-builder] < 3.15.2 |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') |
High
7.5
|
< 3.15.2
|
3.15.2 |
2026-05-12 |
—
|
CVE-2026-4798
The Avada Builder plugin for WordPress contains a flaw in its handling of user input, specifically in the 'product_order' parameter, which allows an attacker to inject malicious SQL code into existing queries. This weakness is present in all versions up to 3.15.1, enabling unauthenticated attackers to extract sensitive database information if WooCommerce was previously installed and then deactivated.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings