CVE-2026-6279Disclosure

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The Avada Builder (fusion-builder) plugin for WordPress is vulnerable to Unauthenticated Remote Code Execution via PHP Function Injection in versions up to and including 3.15.2. This is due to the `wp_conditional_tags` case in `Fusion_Builder_Conditional_Render_Helper::get_value()` passing attacker-controlled values from a base64-decoded JSON blob directly to `call_user_func()` without any allowlist validation. This is exploitable by unauthenticated attackers through the `fusion_get_widget_markup` AJAX endpoint, which is registered for non-privileged (unauthenticated) users via `wp_ajax_nopriv_fusion_get_widget_markup`. The endpoint is protected only by a nonce (`fusion_load_nonce`), but this nonce is generated for user ID 0 and is deterministically exposed in the JavaScript output of any public-facing page containing a Post Cards (`[fusion_post_cards]`) or Table of Contents (`[fusion_table_of_contents]`) element. This makes it possible for unauthenticated attackers to execute arbitrary code on affected sites.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 4 mentions (2026-05-21); latest day: 1
  • 5 total mentions across 2 days

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-05-21: 4Mentions · 2026-05-23: 1Patch / Workaround · 2026-05-21: 1Technical Details · 2026-05-21: 4Technical Details · 2026-05-23: 105-2105-23
Signal classification3 categories
Disclosure
360.0%
General
120.0%
Patch
120.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-214
Disclosure2General1Patch1
2026-05-231
Disclosure1
Full discourse5 posts
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-6279 — CVSS 9.8/10 ██████████ The Avada Builder (fusion-builder) plugin for WordPress is vulnerable to Unauthenticated Remote Code Execution via PHP... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/QG9ji9h6u9

    Post summary

    A critical CVE-2026-6279 affecting the Avada Builder WordPress plugin allows unauthenticated RCE and has a patch now available.

    10000168
    42 followersView on X
  • ThreatAft@ThreatAft
    Disclosure

    🚨 THREE WordPress plugins, THREE critical 9.8 CVSS vulnerabilities, all unauthenticated. 🔴 Avada Builder (CVE-2026-6279) 🔴 Divi Form Builder (CVE-2026-5118) 🔴 BookingPress Pro (CVE-2026-6960) 🔗 https://threataft.com/articles/wordpress-triple-threat-9-8-cvss-avada-divi-bookingpress #CyberSecurity #WordPress #CVE20266279 #CVE20265118

    Post summary

    The article announces three critical, unauthenticated CVEs affecting WordPress plugins, highlighting their high CVSS scores.

    00000261
    26 followersView on X
  • ADK Cyber@ADKCyber
    General

    CVE-2026-6279 (CVSS 9.8) affects the Avada Builder (fusion-builder) plugin for WordPress. Unauthenticated remote code execution is possible in versions up to 3.15.2. via NVD Recent High CVSS 1/2 #CyberSecurity #InfoSec #Vulnerability https://t.co/MRAzu5Qk4z

    Post summary

    A high‑severity RCE vulnerability (CVE‑2026‑6279) affecting Avada Builder is announced, but no exploit code, PoC, or patch information is provided.

    0000097
    81 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-6279 The Avada Builder (fusion-builder) plugin for WordPress is vulnerable to Unauthenticated Remote Code Execution via PHP Function Injection in versions up to and includin… https://www.cve.org/CVERecord?id=CVE-2026-6279 ----- Traducción: CVE-2026-6279 El … http://infoflow.cloud`

    Post summary

    CVE-2026-6279 is disclosed as an unauthenticated RCE vulnerability in the Avada Builder plugin, but no PoC, exploit, patch, or active exploitation details are provided.

    0000083
    79 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-6279 The Avada Builder (fusion-builder) plugin for WordPress is vulnerable to Unauthenticated Remote Code Execution via PHP Function Injection in versions up to and includin… https://www.cve.org/CVERecord?id=CVE-2026-6279

    Post summary

    CVE-2026-6279 reveals an unauthenticated RCE in the Avada Builder WordPress plugin via PHP function injection, with no evidence of exploitation, PoC, or patch details reported.

    00000292
    57.5K followersView on X

Explore more