{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3athemefusionavada/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:themefusion:avada:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-97670"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Avada (Fusion) Builder (\u003c= 7.16.1)"],"_cs_severities":["high"],"_cs_tags":["wordpress","plugin-vulnerability","cve-2026-97670"],"_cs_type":"threat","_cs_vendors":["ThemeFusion"],"content_html":"\u003cp\u003eThe Avada Fusion Builder plugin for WordPress is vulnerable to an authorization bypass flaw (CVE-2026-97670) affecting all versions up to and including 7.16.1. The issue stems from the plugin's failure to verify authorization before dispatching WordPress action hooks parsed from attacker-supplied form data. Specifically, the plugin's dynamic-data token system handles the {action_hook,...} token within form notification email templates without adequate validation. Because the plugin's internal trust gate only inspects 'args' parameters and ignores 'formData' processed during AJAX submissions, an unauthenticated attacker can supply arbitrary hooks. When an Avada form with a notification template is submitted, the plugin executes these hooks, leading to unauthorized state changes. This can result in permanent site content deletion, denial of service, or the invocation of vulnerable third-party handlers. The vulnerability also facilitates a blind arbitrary meta-read, although exfiltration is limited by the plugin's response path.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a WordPress site running a vulnerable version of Avada Fusion Builder.\u003c/li\u003e\n\u003cli\u003eAttacker locates a page containing a published Avada form with AJAX submission enabled.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a POST request to the plugin's public form-submit endpoint containing malicious form data.\u003c/li\u003e\n\u003cli\u003eAttacker inserts a dynamic-data token, such as {action_hook,wp_scheduled_delete}, into the 'formData' parameters.\u003c/li\u003e\n\u003cli\u003eThe plugin parses the 'formData', bypasses the incomplete 'is_content_request_supplied' security check, and fails to validate the hook name.\u003c/li\u003e\n\u003cli\u003eThe plugin dispatches the requested WordPress action hook, executing the core function (e.g., permanent deletion of trashed posts).\u003c/li\u003e\n\u003cli\u003eFinal objective: unauthorized site state modification, site content destruction, or service disruption.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to trigger sensitive WordPress core and plugin-specific action hooks. This leads to the permanent, irreversible destruction of site content including posts, pages, and comments, as well as potential denial of service through auto-update hooks. While the vulnerability also allows for arbitrary meta-reading, observed exploitation vectors center on unauthorized administrative state changes and data loss.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eImmediately update the Avada Fusion Builder plugin to a version released after 7.16.1 to resolve CVE-2026-97670.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for suspicious POST requests to form submission endpoints that include patterns such as '{action_hook' or common WordPress administrative hooks.\u003c/li\u003e\n\u003cli\u003eAudit Avada form configurations to identify and sanitize active notification email templates that use dynamic-data tokens.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-10T05:34:20Z","date_published":"2026-10-10T05:34:20Z","id":"https://feed.craftedsignal.io/briefs/2026-10-avada-builder-auth-bypass/","summary":"An unauthenticated authorization bypass in the Avada Fusion Builder plugin for WordPress allows attackers to trigger arbitrary action hooks via crafted AJAX form submissions.","title":"CVE-2026-97670 Authorization Bypass in Avada Fusion Builder","url":"https://feed.craftedsignal.io/briefs/2026-10-avada-builder-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:themefusion:avada:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}