CVE-2023-39310: WordPress Avada Builder plugin <= 3.11.1 - Authenticated Broken Access Control vulnerability
Published Jun 19, 2024
·Updated
Missing Authorization vulnerability in ThemeFusion Fusion Builder.This issue affects Fusion Builder: from n/a through 3.11.1.
Affected Software
2 affected components
ThemeFusion Fusion Builder>=n/a, <=3.11.1
WordPress Avada Builder<=3.11.1
Remediation
Information
Update to 3.11.2 or a higher version.
Event History
Jun 19, 2024
CVE Published
via MITRE·02:07 PM
Data Sourced
via MITRE·02:07 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-39310?
CVE-2023-39310 has been classified as a critical severity vulnerability due to missing authorization in ThemeFusion Fusion Builder.
2
How do I fix CVE-2023-39310?
To fix CVE-2023-39310, update your ThemeFusion Fusion Builder plugin to version 3.11.2 or later where the vulnerability has been patched.
3
What versions are affected by CVE-2023-39310?
CVE-2023-39310 affects ThemeFusion Fusion Builder versions from n/a to 3.11.1.
4
Is CVE-2023-39310 specific to any WordPress themes?
Yes, CVE-2023-39310 specifically impacts both the ThemeFusion Fusion Builder and WordPress Avada Builder.
5
Can CVE-2023-39310 be exploited remotely?
Yes, CVE-2023-39310 can be exploited remotely if an attacker can access the affected Fusion Builder components.