Vendor
high
threat
CVE-2026-97670 Authorization Bypass in Avada Fusion Builder
1 rule 1 TTP 1 CVEAn unauthenticated authorization bypass in the Avada Fusion Builder plugin for WordPress allows attackers to trigger arbitrary action hooks via crafted AJAX form submissions.
exploited
Avada
wordpress
plugin-vulnerability
cve-2026-97670
1r
1t
1c
critical
advisory
Arbitrary File Write in Avada Theme and Fusion Builder
2 TTPs 1 CVEAn unauthenticated arbitrary file write vulnerability in the Avada WordPress theme and Fusion Builder plugin allows remote attackers to execute arbitrary PHP code and compromise the host.
Avada +1
2t
1c