SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-1386

The Fusion Builder WordPress plugin before 3.6.2, used in the Avada theme, does not validate a parameter in its forms which could be used to initiate arbitrary HTTP requests.

CRITICAL 9.8EPSS 71.4%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 71.4%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.

Description

The Fusion Builder WordPress plugin before 3.6.2, used in the Avada theme, does not validate a parameter in its forms which could be used to initiate arbitrary HTTP requests. The data returned is then reflected back in the application's response. This could be used to interact with hosts on the server's local network bypassing firewalls and access control measures.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
71.43% probability · 99th percentile
CISA KEV
Not listed
Weakness
CWE-918
Affected
fusion builder project/fusion builder · theme-fusion/avada
Source
contact@wpscan.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.