Avada Builder
cpe:2.3:a:theme-fusion:avada_builder:*:*:*:*:wordpress:*:*
- <= 3.15.2
A vulnerability allowing arbitrary file read has been identified in the Avada Builder plugin for WordPress, affecting all versions through 3.15.2. The issue arises in the 'fusion_get_svg_from_file' function, specifically through the 'custom_svg' parameter of the 'fusion_section_separator' shortcode. This vulnerability enables authenticated attackers with Subscriber-level access and above to read arbitrary files on the server, potentially exposing sensitive information. While version 3.15.2 includes a partial patch, the vulnerability is fully addressed in version 3.15.3.
Exploitation of this vulnerability allows for unauthorized reading of server files, which may contain sensitive information.
Users are advised to update to Avada Builder version 3.15.3 or a newer patched version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.