CVE-2026-97670 Authorization Bypass in Avada Fusion Builder
An unauthenticated authorization bypass in the Avada Fusion Builder plugin for WordPress allows attackers to trigger arbitrary action hooks via crafted AJAX form submissions.
CVE search metadata
CVE search record: CVE-2026-97670. Severity: critical. CVSS: 9.1. KEV: no. Product: Avada (Fusion) Builder (<= 7.16.1). Brief: CVE-2026-97670 Authorization Bypass in Avada Fusion Builder. Brief link: https://feed.craftedsignal.io/briefs/2026-10-avada-builder-auth-bypass/
The Avada Fusion Builder plugin for WordPress is vulnerable to an authorization bypass flaw (CVE-2026-97670) affecting all versions up to and including 7.16.1. The issue stems from the plugin's failure to verify authorization before dispatching WordPress action hooks parsed from attacker-supplied form data. Specifically, the plugin's dynamic-data token system handles the {action_hook,...} token within form notification email templates without adequate validation. Because the plugin's internal trust gate only inspects 'args' parameters and ignores 'formData' processed during AJAX submissions, an unauthenticated attacker can supply arbitrary hooks. When an Avada form with a notification template is submitted, the plugin executes these hooks, leading to unauthorized state changes. This can result in permanent site content deletion, denial of service, or the invocation of vulnerable third-party handlers. The vulnerability also facilitates a blind arbitrary meta-read, although exfiltration is limited by the plugin's response path.
Attack Chain
- Attacker identifies a WordPress site running a vulnerable version of Avada Fusion Builder.
- Attacker locates a page containing a published Avada form with AJAX submission enabled.
- Attacker crafts a POST request to the plugin's public form-submit endpoint containing malicious form data.
- Attacker inserts a dynamic-data token, such as {action_hook,wp_scheduled_delete}, into the 'formData' parameters.
- The plugin parses the 'formData', bypasses the incomplete 'is_content_request_supplied' security check, and fails to validate the hook name.
- The plugin dispatches the requested WordPress action hook, executing the core function (e.g., permanent deletion of trashed posts).
- Final objective: unauthorized site state modification, site content destruction, or service disruption.
Impact
Successful exploitation allows unauthenticated attackers to trigger sensitive WordPress core and plugin-specific action hooks. This leads to the permanent, irreversible destruction of site content including posts, pages, and comments, as well as potential denial of service through auto-update hooks. While the vulnerability also allows for arbitrary meta-reading, observed exploitation vectors center on unauthorized administrative state changes and data loss.
Recommendation
- Immediately update the Avada Fusion Builder plugin to a version released after 7.16.1 to resolve CVE-2026-97670.
- Monitor web server logs for suspicious POST requests to form submission endpoints that include patterns such as '{action_hook' or common WordPress administrative hooks.
- Audit Avada form configurations to identify and sanitize active notification email templates that use dynamic-data tokens.
Immediate actions
Upgrade Avada Fusion Builder to a version exceeding 7.16.1
Mitigations
Update Avada Fusion Builder to patched version
CVE-2026-97670
Detection coverage 1
Detect CVE-2026-97670 Exploitation - Suspicious Avada Form Hook Injection
highDetects unauthorized attempts to trigger WordPress hooks via Avada form submission by identifying the {action_hook sequence in HTTP POST requests.
Detection queries are available on the platform. Get full rules →