CVE-2022-1386
The Fusion Builder WordPress plugin before 3.6.2, used in the Avada theme, does not validate a parameter in its forms which could be used to initiate arbitrary HTTP requests.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 71.4%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
The Fusion Builder WordPress plugin before 3.6.2, used in the Avada theme, does not validate a parameter in its forms which could be used to initiate arbitrary HTTP requests. The data returned is then reflected back in the application's response. This could be used to interact with hosts on the server's local network bypassing firewalls and access control measures.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 71.43% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-918
- Affected
- fusion builder project/fusion builder · theme-fusion/avada
- Source
- contact@wpscan.com
References
- https://theme-fusion.com/version-7-6-2-security-update/Patch, Release Notes, Third Party Advisory
- https://wpscan.com/vulnerability/bf7034ab-24c4-461f-a709-3f73988b536bExploit, Third Party Advisory
- https://www.rootshellsecurity.net/rootshell-discovered-a-critical-vulnerability-in-top-wordpress-theme/Patch, Third Party Advisory
- https://theme-fusion.com/version-7-6-2-security-update/Patch, Release Notes, Third Party Advisory
- https://wpscan.com/vulnerability/bf7034ab-24c4-461f-a709-3f73988b536bExploit, Third Party Advisory
- https://www.rootshellsecurity.net/rootshell-discovered-a-critical-vulnerability-in-top-wordpress-theme/Patch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.