CVE-2026-12256: WordPress Fusion Builder plugin <= 3.15.3 - PHP Object Injection vulnerability
Deserialization of Untrusted Data vulnerability in ThemeFusion Fusion Builder fusion-builder allows Object Injection.This issue affects Fusion Builder: from n/a through 3.15.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Fusion Builder pluginto a version that resolves this vulnerability.Fixed in 3.15.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12256?
The severity of CVE-2026-12256 is rated as high with a CVSS score of 8.8.
What is CVE-2026-12256?
CVE-2026-12256 is a PHP Object Injection vulnerability affecting the Avada theme versions up to 3.15.3.
How do I fix CVE-2026-12256?
To fix CVE-2026-12256, upgrade the Avada theme to a version later than 3.15.3.
What impact does CVE-2026-12256 have on my site?
CVE-2026-12256 can allow attackers to exploit PHP Object Injection, leading to potential remote code execution.
Is CVE-2026-12256 easily exploitable?
Yes, CVE-2026-12256 is rated as easily exploitable due to its low authentication and user interaction requirements.