CVE-2026-6279

CRITICAL

The Avada Builder (fusion-builder) plugin for WordPress is vulnerable to Unauthenticated Remote Code Execution via PHP Function Injection in versions up to and including 3.15.2. This is due to the ...

Affects 0 products across 8 vendors.

BCS6.92
CVSS 3.19.8
EPSS2.2%
Percentile81th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-74: Injection

Parent class for all injection vulnerabilities where attacker-supplied data is interpreted as code or commands.

Related Attack Patterns (CAPEC)
CAPEC-3 Using Leading 'Ghost' Character Sequences to Bypass Input Filters
via CWE-74
CAPEC-7 Blind SQL Injection
via CWE-74
CAPEC-8 Buffer Overflow in an API Call
via CWE-74
CAPEC-9 Buffer Overflow in Local Command-Line Utilities
via CWE-74
CAPEC-10 Buffer Overflow via Environment Variables
via CWE-74
Show all 37
via CWE-74
via CWE-74
via CWE-74
via CWE-74
via CWE-74
via CWE-74
via CWE-74
via CWE-74
via CWE-74
via CWE-74
via CWE-74
via CWE-74
via CWE-74
via CWE-74
via CWE-74
via CWE-74
via CWE-74
via CWE-74
via CWE-74
via CWE-74
via CWE-74
via CWE-74
via CWE-74
via CWE-74
via CWE-74
via CWE-74
via CWE-74
via CWE-74
via CWE-74
via CWE-74
via CWE-74
via CWE-74

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

The Avada Builder (fusion-builder) plugin for WordPress is vulnerable to Unauthenticated Remote Code Execution via PHP Function Injection in versions up to and including 3.15.2.

BSID: BS-2026-GLOBAL-271132-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2026-6279?
The Avada Builder (fusion-builder) plugin for WordPress is vulnerable to Unauthenticated Remote Code Execution via PHP Function Injection in versions up to and including 3.15.2.
What is the CVSS score for CVE-2026-6279?
CVE-2026-6279 has CVSS 9.8 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. EPSS: 2.2%.
Is CVE-2026-6279 actively exploited?
No confirmed active exploitation of CVE-2026-6279 as of 2026-07-24.
How do I remediate CVE-2026-6279?
Priority: IMMEDIATE.
What systems are affected by CVE-2026-6279?
CVE-2026-6279 affects: Ajax, Avada, Blob, Element, Fusion, Javascript, Plugin, Wordpress.
Vulnerability Details
CVE IDCVE-2026-6279
BSIDBS-2026-GLOBAL-271132-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published2026-05-21
Last Modified2026-07-23
ICS Relevance0%
Weakness (CWE)
SourceNVD
Official Description

The Avada Builder (fusion-builder) plugin for WordPress is vulnerable to Unauthenticated Remote Code Execution via PHP Function Injection in versions up to and including 3.15.2. This is due to the `wp_conditional_tags` case in `Fusion_Builder_Conditional_Render_Helper::get_value()` passing attacker-controlled values from a base64-decoded JSON blob directly to `call_user_func()` without any allowlist validation. This is exploitable by unauthenticated attackers through the `fusion_get_widget_markup` AJAX endpoint, which is registered for non-privileged (unauthenticated) users via `wp_ajax_nopriv_fusion_get_widget_markup`. The endpoint is protected only by a nonce (`fusion_load_nonce`), but this nonce is generated for user ID 0 and is deterministically exposed in the JavaScript output of any public-facing page containing a Post Cards (`[fusion_post_cards]`) or Table of Contents (`[fusion_table_of_contents]`) element. This makes it possible for unauthenticated attackers to execute arbitrary code on affected sites.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability arises from the `wp_conditional_tags` case in `Fusion_Builder_Conditional_Render_Helper::get_value()` method, which passes attacker-controlled values from a base64-decoded JSON blob directly to `call_user_func()` without any allowlist validation.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Ajax —
Avada —
Blob —
Element —
Fusion —
Javascript —
Plugin —
Wordpress —
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 98 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hash7f67b70549470cba35f024025b3249bf727482f2124c53a64499c6041557d7debf751bff7d7a47e53bd305dac0f7ac2b2383d80998b9f4b8486488be696997b8
Related CVEs affecting Ajax
CVE-2024-49254 10.0 Improper Control of Generation of Code ('Code Injection') vulnerability in su... CVE-2024-2086 10.0 The Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Ga... CVE-2024-3820 10.0 The wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin... CVE-2024-51482 9.9 ZoneMinder is a free, open source closed-circuit television software applicat... CVE-2021-47932 9.8 WordPress TheCartPress 1.5.3.6 contains an unauthenticated privilege escalati...
View all Ajax CVEs →

Critical Severity - Know Your Exposure

A CVSS 9.8 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →