9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
The Fusion Builder WordPress plugin before 3.6.2, used in the Avada theme, does not validate a parameter in its forms which could be used to initiate arbitrary HTTP requests. The data returned is then reflected back in the application's response. This could be used to interact with hosts on the server's local network bypassing firewalls and access control measures.
Affected (2)
Products: Fusion Builder Project: Fusion Builder · Theme Fusion: Avada
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.6.2 | |
| Before 7.6.2 |
References (6)
Source: contact@wpscan.com
PatchRelease NotesThird Party Advisory
Source: contact@wpscan.com
ExploitThird Party Advisory
Source: contact@wpscan.com
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchRelease NotesThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Timeline
No history available yet.