CVE-2026-12256: WordPress Avada theme <= 3.15.3 - PHP Object Injection vulnerability
Published Jun 16, 2026
·Updated
Contributor PHP Object Injection in Avada <= 3.15.3 versions.
Affected Software
1 affected component
ThemeFusion Avada<=3.15.3
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Avada Themeto a version that resolves this vulnerability.Fixed in 3.15.4
Event History
Jun 16, 2026
CVE Published
via MITRE·08:57 PM
Data Sourced
via MITRE·08:57 PM
RemedyDescriptionSeverityWeakness
Jun 17, 2026
Data Sourced
via NVD·01:19 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-12256?
The severity of CVE-2026-12256 is rated as high with a CVSS score of 8.8.
2
What is CVE-2026-12256?
CVE-2026-12256 is a PHP Object Injection vulnerability affecting the Avada theme versions up to 3.15.3.
3
How do I fix CVE-2026-12256?
To fix CVE-2026-12256, upgrade the Avada theme to a version later than 3.15.3.
4
What impact does CVE-2026-12256 have on my site?
CVE-2026-12256 can allow attackers to exploit PHP Object Injection, leading to potential remote code execution.
5
Is CVE-2026-12256 easily exploitable?
Yes, CVE-2026-12256 is rated as easily exploitable due to its low authentication and user interaction requirements.