Description
Contributor Arbitrary File Deletion in Fusion Builder <= 3.15.4 versions.
Published: 2026-06-17
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An arbitrary file deletion flaw was discovered in the WordPress Fusion Builder plugin versions 3.15.4 and earlier. The vulnerability allows a user with contributor rights to delete arbitrary files on the server hosting the WordPress installation, potentially removing critical configuration files, themes, or other content. This can lead to site downtime, data loss, and a breach of data integrity for the affected environment. The weakness corresponds to CWE-22, indicating an improper use of file path handling that lacks proper validation.

Affected Systems

All installations of the ThemeFusion Fusion Builder plugin that are at version 3.15.4 or older are affected. The CVE specifies that any instance using these legacy plugin releases is vulnerable; no specific WordPress core version requirement is noted beyond the plugin.

Risk and Exploitability

The vulnerability carries a CVSS score of 7.7, indicating medium‑to‑high severity. The EPSS score is not available, and the flaw is not listed in the CISA KEV catalog. The likely exploitation path involves an authenticated contributor user invoking the plugin’s file deletion endpoint; no additional network or remote attack vector is described, so the attack vector is inferred to be local or authenticated within the WordPress environment. This means that the risk is highest for sites where contributor accounts are robust or lack proper segregation of duties, and the potential damage is significant due to the ability to remove arbitrary files.

Generated by OpenCVE AI on June 18, 2026 at 13:56 UTC.

Remediation

Vendor Solution

Update the WordPress Fusion Builder Plugin to the latest available version (at least 3.15.5).


OpenCVE Recommended Actions

  • Upgrade the Fusion Builder plugin to version 3.15.5 or later.
  • Restrict contributor permissions to remove file deletion capability.
  • Restore deleted files from backups.

Generated by OpenCVE AI on June 18, 2026 at 13:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 18 Jun 2026 04:45:00 +0000

Type Values Removed Values Added
First Time appeared Themefusion
Themefusion fusion Builder
Wordpress
Wordpress wordpress
Vendors & Products Themefusion
Themefusion fusion Builder
Wordpress
Wordpress wordpress
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 17 Jun 2026 14:00:00 +0000

Type Values Removed Values Added
Description Contributor Arbitrary File Deletion in Fusion Builder <= 3.15.4 versions.
Title WordPress Fusion Builder plugin <= 3.15.4 - Arbitrary File Deletion vulnerability
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H'}


Subscriptions

Themefusion Fusion Builder
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-06-17T15:38:27.177Z

Reserved: 2026-06-12T09:15:46.417Z

Link: CVE-2026-54193

cve-icon Vulnrichment

Updated: 2026-06-17T15:38:20.708Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-18T14:00:16Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')