Impact
The flaw lies in the plugin’s handling of the 'size' attribute within a shortcode. Because the attribute value is never properly sanitized or escaped, an authenticated user with contributor‑level access can embed a script that will be stored and later executed by anyone who views the affected page. This results in a classic Stored XSS scenario, enabling attackers to steal cookies, deface content, or perform other client‑side attacks without needing to compromise the server itself.
Affected Systems
Avada (Fusion) Builder – a WordPress plugin supplied by themefusion. All releases up to and including version 3.15.6 are vulnerable. The vulnerability affects any WordPress site that has this plugin installed and permits contributor‑level users to edit content.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderately severe vulnerability. Because it requires authenticated access, exploitation is limited to users who already have contributor or higher roles, yet the injected script runs for every visitor to the affected content. No KEV listing or EPSS data is available, but the moderate severity and potential widespread impact mean that any site should treat this as a priority fix.
OpenCVE Enrichment