Description
Missing Authorization vulnerability in ThemeFusion Fusion Builder fusion-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fusion Builder: from n/a through < 3.15.0.
Published: 2026-03-13
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Broken Access Control
Action: Update Plugin
AI Analysis

Impact

The vulnerability is a missing authorization check in the ThemeFusion Fusion Builder WordPress plugin. This flaw allows exploitation of incorrectly configured access control security levels, leading to a broken access control weakness classified as CWE-862.

Affected Systems

All WordPress sites that use the Fusion Builder plugin version earlier than 3.15.0 are affected. The vulnerability exists in all releases from unspecified starting versions up to, but not including, 3.15.0.

Risk and Exploitability

The CVSS score of 6.3 indicates medium severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker could interact with the plugin’s web interface to gain unauthorized access to protected resources.

Generated by OpenCVE AI on March 19, 2026 at 15:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Fusion Builder plugin to version 3.15.0 or later.
  • If an update is not possible immediately, disable or uninstall the plugin to prevent further exploitation.
  • Verify that plugin files have appropriate permissions and that no unauthorized files are present.
  • Monitor site logs for unusual activity related to the Fusion Builder endpoints.

Generated by OpenCVE AI on March 19, 2026 at 15:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 16 Mar 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Themefusion
Themefusion fusion Builder
Wordpress
Wordpress wordpress
Vendors & Products Themefusion
Themefusion fusion Builder
Wordpress
Wordpress wordpress

Fri, 13 Mar 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 13 Mar 2026 12:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in ThemeFusion Fusion Builder fusion-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fusion Builder: from n/a through < 3.15.0.
Title WordPress Fusion Builder plugin < 3.15.0 - Broken Access Control vulnerability
Weaknesses CWE-862
References

Subscriptions

Themefusion Fusion Builder
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-01T14:16:19.315Z

Reserved: 2026-03-12T11:11:40.509Z

Link: CVE-2026-32451

cve-icon Vulnrichment

Updated: 2026-03-13T18:51:29.055Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-03-13T19:55:06.340

Modified: 2026-03-16T14:53:46.157

Link: CVE-2026-32451

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-23T12:03:14Z

Weaknesses