<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Avada (Fusion) Builder (&lt;= 7.16.1) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/avada-fusion-builder--7.16.1/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 10 Oct 2026 05:34:20 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/avada-fusion-builder--7.16.1/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>CVE-2026-97670 Authorization Bypass in Avada Fusion Builder</title><link>https://feed.craftedsignal.io/briefs/2026-10-avada-builder-auth-bypass/</link><pubDate>Sat, 10 Oct 2026 05:34:20 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-avada-builder-auth-bypass/</guid><description>An unauthenticated authorization bypass in the Avada Fusion Builder plugin for WordPress allows attackers to trigger arbitrary action hooks via crafted AJAX form submissions.</description><content:encoded><![CDATA[<p>The Avada Fusion Builder plugin for WordPress is vulnerable to an authorization bypass flaw (CVE-2026-97670) affecting all versions up to and including 7.16.1. The issue stems from the plugin's failure to verify authorization before dispatching WordPress action hooks parsed from attacker-supplied form data. Specifically, the plugin's dynamic-data token system handles the {action_hook,...} token within form notification email templates without adequate validation. Because the plugin's internal trust gate only inspects 'args' parameters and ignores 'formData' processed during AJAX submissions, an unauthenticated attacker can supply arbitrary hooks. When an Avada form with a notification template is submitted, the plugin executes these hooks, leading to unauthorized state changes. This can result in permanent site content deletion, denial of service, or the invocation of vulnerable third-party handlers. The vulnerability also facilitates a blind arbitrary meta-read, although exfiltration is limited by the plugin's response path.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker identifies a WordPress site running a vulnerable version of Avada Fusion Builder.</li>
<li>Attacker locates a page containing a published Avada form with AJAX submission enabled.</li>
<li>Attacker crafts a POST request to the plugin's public form-submit endpoint containing malicious form data.</li>
<li>Attacker inserts a dynamic-data token, such as {action_hook,wp_scheduled_delete}, into the 'formData' parameters.</li>
<li>The plugin parses the 'formData', bypasses the incomplete 'is_content_request_supplied' security check, and fails to validate the hook name.</li>
<li>The plugin dispatches the requested WordPress action hook, executing the core function (e.g., permanent deletion of trashed posts).</li>
<li>Final objective: unauthorized site state modification, site content destruction, or service disruption.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to trigger sensitive WordPress core and plugin-specific action hooks. This leads to the permanent, irreversible destruction of site content including posts, pages, and comments, as well as potential denial of service through auto-update hooks. While the vulnerability also allows for arbitrary meta-reading, observed exploitation vectors center on unauthorized administrative state changes and data loss.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Immediately update the Avada Fusion Builder plugin to a version released after 7.16.1 to resolve CVE-2026-97670.</li>
<li>Monitor web server logs for suspicious POST requests to form submission endpoints that include patterns such as '{action_hook' or common WordPress administrative hooks.</li>
<li>Audit Avada form configurations to identify and sanitize active notification email templates that use dynamic-data tokens.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category><category>wordpress</category><category>plugin-vulnerability</category><category>cve-2026-97670</category></item></channel></rss>