Impact
The Avada (Fusion) Builder plugin is vulnerable to an authorization bypass that allows unauthenticated users to provide a form field value that is used as the name of a WordPress action hook. When this hook is triggered the plugin neither verifies proper permissions nor checks that the supplied action name is safe. As a result attackers can invoke any registered WordPress action, including destructive hooks such as wp_scheduled_delete which permanently deletes trashed posts, pages, and comments. The same flaw also permits blind reading of user or post meta that is only forwarded to the site owner, and can trigger other third‑party hooks that may grant broad write privileges or cause denial of service. This yields a high‑severity impact on data integrity and availability.
Affected Systems
The vulnerability affects all versions of the Avada (Fusion) Builder plugin for WordPress up to and including version 7.16.1. The plugin is distributed by themefusion:Avada (Fusion) Builder and can be found in any WordPress installation that includes the plugin. Version information is provided explicitly in the description; versions newer than 7.16.1 are not affected.
Risk and Exploitability
The CVSS score of 9.1 indicates critical severity, and no EPSS score means the exploitation probability is currently unknown but could be significant given the public nature of the form endpoint. The plugin does not list this vulnerability in the CISA KEV catalog, but its impact is still substantial. Exploitation requires a publicly accessible Avada form that submits via AJAX and a notification email template that contains the {action_hook} dynamic‑data token, which is a default configuration. Attackers can supply arbitrary hook names in the form field, causing the server to execute those hooks. Because no authentication is required and the action is performed server‑side, the vulnerability is effectively a remote code execution and state modification attack. The potential for irreversible content loss, denial of service, and privilege escalation makes this flaw a priority to remediate.
OpenCVE Enrichment