PLUGIN SECURITY
Is Avada Builder safe?
Site Reviews is the best free reviews plugin. It integrates with WooCommerce & SureCart and works just like reviews on Amazon, Tripadvisor, and Yelp.
What this plugin does
- Slug:
fusion-builder - Author: Gemini Labs
- 60000+ active installs
- 98/100 rating (371 reviews on wordpress.org)
- 3389351 all-time downloads
- On WordPress.org since 2016-10-22
business reviewsproduct reviewsratingsreviewstestimonials
Maintenance status
- Latest known version: 8.2.0
- Last updated: 2026-08-23 11:17am GMT
- Tested up to WordPress: 7.1
- Requires PHP: 8.1.2+
Known vulnerabilities
25 known CVEs on file for Avada Builder.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-18431 | Fusion Builder [fusion-builder] < 3.16.1 | Missing Authorization | Critical 9.8 | < 3.16.1 | 3.16.1 | 2026-08-25 | ✓ fixed in latest |
| CVE-2026-16654 | Fusion Builder [fusion-builder] < 3.16 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 3.16 | 3.16 | 2026-08-25 | ✓ fixed in latest |
| CVE-2026-12536 | Fusion Builder [fusion-builder] < 3.15.6 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 3.15.6 | 3.15.6 | 2026-07-13 | ✓ fixed in latest |
| CVE-2026-8713 | Fusion Builder [fusion-builder] < 3.15.4 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | Critical 9.1 | < 3.15.4 | 3.15.4 | 2026-06-18 | ✓ fixed in latest |
| CVE-2026-56008 | Fusion Builder [fusion-builder] < 3.15.5 | Incorrect Privilege Assignment | High 8.8 | < 3.15.5 | 3.15.5 | 2026-06-18 | ✓ fixed in latest |
| CVE-2026-54193 | Fusion Builder [fusion-builder] < 3.15.5 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | High 7.7 | < 3.15.5 | 3.15.5 | 2026-06-16 | ✓ fixed in latest |
| CVE-2026-54194 | Fusion Builder [fusion-builder] < 3.15.5 | Deserialization of Untrusted Data | Critical 9.8 | < 3.15.5 | 3.15.5 | 2026-06-15 | ✓ fixed in latest |
| CVE-2026-6279 | Fusion Builder [fusion-builder] < 3.15.3 | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') | Critical 9.8 | < 3.15.3 | 3.15.3 | 2026-05-20 | ✓ fixed in latest |
+ 21 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-1543 | Fusion Builder [fusion-builder] < 3.15.3 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 3.15.3 | 3.15.3 | 2026-05-20 | ✓ fixed in latest |
| CVE-2026-4782 | Fusion Builder [fusion-builder] < 3.15.3 | Absolute Path Traversal | Medium 6.5 | < 3.15.3 | 3.15.3 | 2026-05-12 | ✓ fixed in latest |
| CVE-2026-4798 | Fusion Builder [fusion-builder] < 3.15.2 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | High 7.5 | < 3.15.2 | 3.15.2 | 2026-05-12 | ✓ fixed in latest |
| CVE-2026-32542 | Fusion Builder [fusion-builder] < 3.15.0 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 7.1 | < 3.15.0 | 3.15.0 | 2026-03-20 | ✓ fixed in latest |
| CVE-2026-32452 | Fusion Builder [fusion-builder] < 3.15.0 | Missing Authorization | Medium 5.3 | < 3.15.0 | 3.15.0 | 2026-03-10 | ✓ fixed in latest |
| CVE-2026-32451 | Fusion Builder [fusion-builder] < 3.15.0 | Missing Authorization | Medium 6.5 | < 3.15.0 | 3.15.0 | 2026-03-10 | ✓ fixed in latest |
| CVE-2026-25472 | Fusion Builder [fusion-builder] < 3.14.2 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 3.14.2 | 3.14.2 | 2026-01-15 | ✓ fixed in latest |
| CVE-2025-49940 | Fusion Builder [fusion-builder] < 3.13.3 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 3.13.3 | 3.13.3 | 2025-10-03 | ✓ fixed in latest |
| CVE-2024-13345 | Fusion Builder [fusion-builder] < 3.11.14 | Improper Control of Generation of Code ('Code Injection') | High 7.3 | < 3.11.14 | 3.11.14 | 2025-02-12 | ✓ fixed in latest |
| CVE-2024-12477 | Fusion Builder [fusion-builder] < 3.11.12 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 3.11.12 | 3.11.12 | 2025-01-22 | ✓ fixed in latest |
| CVE-2024-12335 | Fusion Builder [fusion-builder] < 3.11.13 | Authorization Bypass Through User-Controlled Key | Medium 4.3 | < 3.11.13 | 3.11.13 | 2024-12-24 | ✓ fixed in latest |
| CVE-2024-5628 | Fusion Builder [fusion-builder] < 3.11.10 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 3.11.10 | 3.11.10 | 2024-09-12 | ✓ fixed in latest |
| CVE-2023-39311 | Fusion Builder [fusion-builder] < 3.11.2 | Cross-Site Request Forgery (CSRF) | High 7.1 | < 3.11.2 | 3.11.2 | 2023-08-10 | ✓ fixed in latest |
| CVE-2023-39310 | Fusion Builder [fusion-builder] < 3.11.2 | Missing Authorization | Medium 5.4 | < 3.11.2 | 3.11.2 | 2023-08-10 | ✓ fixed in latest |
| CVE-2023-39309 | Fusion Builder [fusion-builder] < 3.11.2 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | High 8.5 | < 3.11.2 | 3.11.2 | 2023-08-10 | ✓ fixed in latest |
| CVE-2023-39306 | Fusion Builder [fusion-builder] < 3.11.2 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 7.1 | < 3.11.2 | 3.11.2 | 2023-08-10 | ✓ fixed in latest |
| CVE-2022-1386 | Fusion Builder [fusion-builder] < 3.6.2 | Server-Side Request Forgery (SSRF) | Critical 9.8 | < 3.6.2 | 3.6.2 | 2022-04-19 | ✓ fixed in latest |
| — | Fusion Builder [fusion-builder] < 3.11.15 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 3.11.15 | 3.11.15 | 0000-00-00 | ✓ fixed in latest |
| — | Fusion Builder [fusion-builder] < 3.12.2 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 3.12.2 | 3.12.2 | 0000-00-00 | ✓ fixed in latest |
| — | Fusion Builder [fusion-builder] < 3.15.2 | — | Medium 4.3 | < 3.15.2 | 3.15.2 | 0000-00-00 | ✓ fixed in latest |
| — | Fusion Builder [fusion-builder] < 3.15.2 | — | Medium 5.4 | < 3.15.2 | 3.15.2 | 0000-00-00 | ✓ fixed in latest |
How to fix it
Keep Avada Builder updated — 8.2.0 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- WP Google Review Slider — 30000+ active installs — 98/100 (369) — max PHP 8.4
- ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema — 7000+ active installs — 90/100 (85) — max PHP <8.0
- Gutena Star Ratings — 1000+ active installs — max PHP 8.4
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.