CVE-2026-6279
The Avada Builder (fusion-builder) plugin for WordPress is vulnerable to Unauthenticated Remote Code Execution via PHP Function Injection in versions up to and including 3.15.2. This is due to the ...
Affects 0 products across 8 vendors.
Parent class for all injection vulnerabilities where attacker-supplied data is interpreted as code or commands.
Show all 37
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
The Avada Builder (fusion-builder) plugin for WordPress is vulnerable to Unauthenticated Remote Code Execution via PHP Function Injection in versions up to and including 3.15.2.
BSID: BS-2026-GLOBAL-271132-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2026-6279?
What is the CVSS score for CVE-2026-6279?
Is CVE-2026-6279 actively exploited?
How do I remediate CVE-2026-6279?
What systems are affected by CVE-2026-6279?
| CVE ID | CVE-2026-6279 |
|---|---|
| BSID | BS-2026-GLOBAL-271132-C BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Published | 2026-05-21 |
| Last Modified | 2026-07-23 |
| ICS Relevance | 0% |
| Weakness (CWE) | |
| Source | NVD |
The Avada Builder (fusion-builder) plugin for WordPress is vulnerable to Unauthenticated Remote Code Execution via PHP Function Injection in versions up to and including 3.15.2. This is due to the `wp_conditional_tags` case in `Fusion_Builder_Conditional_Render_Helper::get_value()` passing attacker-controlled values from a base64-decoded JSON blob directly to `call_user_func()` without any allowlist validation. This is exploitable by unauthenticated attackers through the `fusion_get_widget_markup` AJAX endpoint, which is registered for non-privileged (unauthenticated) users via `wp_ajax_nopriv_fusion_get_widget_markup`. The endpoint is protected only by a nonce (`fusion_load_nonce`), but this nonce is generated for user ID 0 and is deterministically exposed in the JavaScript output of any public-facing page containing a Post Cards (`[fusion_post_cards]`) or Table of Contents (`[fusion_table_of_contents]`) element. This makes it possible for unauthenticated attackers to execute arbitrary code on affected sites.
Source: NIST NVD / MITRE CVE Database
The vulnerability arises from the `wp_conditional_tags` case in `Fusion_Builder_Conditional_Render_Helper::get_value()` method, which passes attacker-controlled values from a base64-decoded JSON blob directly to `call_user_func()` without any allowlist validation.
Exploitation Likelihood: CRITICAL
| Vendor | Product | Fixed Version |
|---|---|---|
| Ajax | — | — |
| Avada | — | — |
| Blob | — | — |
| Element | — | — |
| Fusion | — | — |
| Javascript | — | — |
| Plugin | — | — |
| Wordpress | — | — |
No patch URL on record. Monitor vendor security advisories directly.
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
SAGE Enrichment Record — provenance & audit hash
| Model | /workspace/models/qwen2.5-coder-32b-instruct-bf16 |
|---|---|
| Confidence | HIGH |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | 7f67b70549470cba35f024025b3249bf727482f2124c53a64499c6041557d7debf751bff7d7a47e53bd305dac0f7ac2b2383d80998b9f4b8486488be696997b8 |
Critical Severity - Know Your Exposure
A CVSS 9.8 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.
Check Your Assets Free →