CVE-2026-1543: Avada (Fusion) Builder <= 3.15.2 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Multiple Shortcodes
The Avada (Fusion) Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple shortcodes in all versions up to, and including, 3.15.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user (typically an administrator) accesses a page displaying dynamic user data (such as via the Dynamic Data feature pulling user biographical information).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1543?
CVE-2026-1543 is rated as a high severity vulnerability due to its potential to allow authenticated users to execute malicious scripts.
How do I fix CVE-2026-1543?
To fix CVE-2026-1543, update the Avada (Fusion) Builder plugin to version 3.15.3 or later.
Who is affected by CVE-2026-1543?
CVE-2026-1543 affects all users of the Avada (Fusion) Builder plugin for WordPress versions up to and including 3.15.2.
What type of vulnerability is CVE-2026-1543?
CVE-2026-1543 is a stored cross-site scripting vulnerability that can be exploited through multiple shortcodes.
What can an attacker do with CVE-2026-1543?
An attacker can leverage CVE-2026-1543 to inject malicious scripts into posts or pages that could compromise users visiting those pages.