CVE-2026-54193: WordPress Fusion Builder plugin <= 3.15.4 - Arbitrary File Deletion vulnerability
Published Jun 17, 2026
·Updated
Contributor Arbitrary File Deletion in Fusion Builder <= 3.15.4 versions.
Affected Software
1 affected component
ThemeFusion Fusion Builder<=3.15.4
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/fusion-builderto a version that resolves this vulnerability.Fixed in 3.15.5
Event History
Jun 17, 2026
CVE Published
via MITRE·12:47 PM
Data Sourced
via MITRE·12:47 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·02:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-54193?
CVE-2026-54193 has a severity rating of high with a score of 7.7.
2
What systems are affected by CVE-2026-54193?
CVE-2026-54193 affects the ThemeFusion Fusion Builder plugin versions up to 3.15.4.
3
How do I fix CVE-2026-54193?
To fix CVE-2026-54193, it is recommended to update the Fusion Builder plugin to a version higher than 3.15.4.
4
What type of vulnerability is CVE-2026-54193?
CVE-2026-54193 is characterized as an Arbitrary File Deletion vulnerability due to a path traversal issue.
5
What impact does CVE-2026-54193 have?
CVE-2026-54193 allows contributors to delete arbitrary files, potentially compromising the integrity of a WordPress site.