Description
The Avada (Fusion) Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.16.1. This is due to the plugin not properly verifying authorization before dispatching a WordPress action hook whose name is taken from an attacker-supplied form-field value (via the notification email_message [field] placeholder and the {action_hook,...} dynamic-data token; the 3.16.1 trust gate is_content_request_supplied() only inspects $_POST['args']/$_GET['args'], never the $_POST['formData'] the public form-submit endpoint parses). This makes it possible for unauthenticated attackers to invoke arbitrary WordPress action hooks (multiple per request), causing state changes up to permanent, irreversible destruction of site content: a verified unauthenticated request permanently deleted trashed posts, pages, and comments via the core wp_scheduled_delete action. Other non-deny-listed hooks extend the impact to denial of service (e.g. wp_maybe_auto_update) and, where vulnerable third-party handlers are installed, further privileged writes. The same unauthenticated dynamic-data pipeline additionally exposes a blind arbitrary user/post-meta read; the read result is delivered only to the site owner and is not attacker-exfiltrable through the plugin's own email/response paths. Exploitation requires a published Avada form with AJAX submission and a notification whose email_message template includes an [all_fields] or explicit [field] placeholder - the default form configuration.
Published: 2026-10-10
Score: 9.1 Critical
EPSS: n/a
KEV: No
Impact: Arbitrary WordPress Action Execution
Action: Immediate Patch
AI Analysis

Impact

The Avada (Fusion) Builder plugin is vulnerable to an authorization bypass that allows unauthenticated users to provide a form field value that is used as the name of a WordPress action hook. When this hook is triggered the plugin neither verifies proper permissions nor checks that the supplied action name is safe. As a result attackers can invoke any registered WordPress action, including destructive hooks such as wp_scheduled_delete which permanently deletes trashed posts, pages, and comments. The same flaw also permits blind reading of user or post meta that is only forwarded to the site owner, and can trigger other third‑party hooks that may grant broad write privileges or cause denial of service. This yields a high‑severity impact on data integrity and availability.

Affected Systems

The vulnerability affects all versions of the Avada (Fusion) Builder plugin for WordPress up to and including version 7.16.1. The plugin is distributed by themefusion:Avada (Fusion) Builder and can be found in any WordPress installation that includes the plugin. Version information is provided explicitly in the description; versions newer than 7.16.1 are not affected.

Risk and Exploitability

The CVSS score of 9.1 indicates critical severity, and no EPSS score means the exploitation probability is currently unknown but could be significant given the public nature of the form endpoint. The plugin does not list this vulnerability in the CISA KEV catalog, but its impact is still substantial. Exploitation requires a publicly accessible Avada form that submits via AJAX and a notification email template that contains the {action_hook} dynamic‑data token, which is a default configuration. Attackers can supply arbitrary hook names in the form field, causing the server to execute those hooks. Because no authentication is required and the action is performed server‑side, the vulnerability is effectively a remote code execution and state modification attack. The potential for irreversible content loss, denial of service, and privilege escalation makes this flaw a priority to remediate.

Generated by OpenCVE AI on October 10, 2026 at 05:35 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Avada (Fusion) Builder plugin to version 7.16.2 or later to patch the authorization bypass.
  • Remove or disable any form notifications that use the {action_hook} dynamic‑data token or placeholders that could expose WordPress action names until the plugin is updated.
  • Restrict public form access or require authenticated users for the form’s AJAX submission endpoint until the patch is applied.

Generated by OpenCVE AI on October 10, 2026 at 05:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 04:30:00 +0000

Type Values Removed Values Added
Description The Avada (Fusion) Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.16.1. This is due to the plugin not properly verifying authorization before dispatching a WordPress action hook whose name is taken from an attacker-supplied form-field value (via the notification email_message [field] placeholder and the {action_hook,...} dynamic-data token; the 3.16.1 trust gate is_content_request_supplied() only inspects $_POST['args']/$_GET['args'], never the $_POST['formData'] the public form-submit endpoint parses). This makes it possible for unauthenticated attackers to invoke arbitrary WordPress action hooks (multiple per request), causing state changes up to permanent, irreversible destruction of site content: a verified unauthenticated request permanently deleted trashed posts, pages, and comments via the core wp_scheduled_delete action. Other non-deny-listed hooks extend the impact to denial of service (e.g. wp_maybe_auto_update) and, where vulnerable third-party handlers are installed, further privileged writes. The same unauthenticated dynamic-data pipeline additionally exposes a blind arbitrary user/post-meta read; the read result is delivered only to the site owner and is not attacker-exfiltrable through the plugin's own email/response paths. Exploitation requires a published Avada form with AJAX submission and a notification whose email_message template includes an [all_fields] or explicit [field] placeholder - the default form configuration.
Title Avada (Fusion) Builder <= 7.16.1 - Unauthenticated Arbitrary WordPress Action Invocation via '{action_hook}' Dynamic-Data Token in Form Field
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-10T04:26:48.734Z

Reserved: 2026-09-24T20:29:38.773Z

Link: CVE-2026-97670

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T05:16:40.850

Modified: 2026-10-10T05:16:40.850

Link: CVE-2026-97670

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T05:45:17Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')