WP Clinic
Log in Sign up

CVE · High

CVE-2026-56008 — Fusion Builder [fusion-builder] < 3.15.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-56008 Fusion Builder [fusion-builder] < 3.15.5 Incorrect Privilege Assignment High 8.8 < 3.15.5 3.15.5 2026-06-18

CVE-2026-56008

The Avada (Fusion) Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.15.4. This makes it possible for authenticated attackers, with Contributor-level access and above, to elevate their privileges to that of an administrator.

Source: Wordfence

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.