CVE-2025-6747: Avada (Fusion) Builder <= 3.12.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The Avada (Fusion) Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fusionmap' shortcode in all versions up to, and including, 3.12.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6747?
The severity of CVE-2025-6747 is considered high due to the potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2025-6747?
To fix CVE-2025-6747, update the Avada Builder plugin to version 3.12.2 or later.
What versions are affected by CVE-2025-6747?
CVE-2025-6747 affects all versions of the Avada Builder plugin up to and including version 3.12.1.
What is the impact of CVE-2025-6747?
The impact of CVE-2025-6747 allows attackers to execute malicious scripts in the context of the user's session.
Who is impacted by CVE-2025-6747?
Website owners using the Avada Builder plugin for WordPress are impacted by CVE-2025-6747.