CVE · High

CVE-2026-54193 — Fusion Builder [fusion-builder] < 3.15.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-54193 Fusion Builder [fusion-builder] < 3.15.5 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') High 7.7 < 3.15.5 3.15.5 2026-06-16

CVE-2026-54193

The Avada Builder plugin for WordPress contains a flaw in its file path validation mechanism. This weakness allows authorized users with at least Contributor-level access to erase any file on the system, posing a significant risk if sensitive files like the server's configuration are targeted.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.