External risk intelligence

Avada Builder WordPress Plugin Authorization Bypass Leading to Site Destruction

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-97670

The vulnerability exists in a WordPress plugin within a public-facing form submission endpoint. Because it allows unauthenticated attackers to interact with site actions via common form configurations that are typically accessible to any site visitor, the vulnerable surface is exposed by design as part of normal public web operations.

Code Injection

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This critical vulnerability affects the Avada (Fusion) Builder plugin for WordPress, allowing unauthenticated attackers to potentially destroy site content or cause denial of service by exploiting a flaw in how the plugin handles form submissions. The issue stems from insufficient authorization checks before executing specific WordPress actions, which could be triggered through specially crafted form notifications.

  • Unauthenticated attackers can delete site content.
  • Leadership should track if this plugin is used internally.
  • Confirm relevance and assess exposure risk.

Attack Path

How an attacker could exploit the issue

An attacker can bypass authorization to directly trigger site actions by submitting a specially crafted form. This involves exploiting how the plugin processes form data and notification templates, allowing invocation of arbitrary WordPress hooks. This can lead to irreversible destruction of site content, denial of service, or further unauthorized modifications.

  • Unauthenticated access to a published form.
  • Submitting a form with malicious notification data.
  • Irreversible content destruction or denial of service.

Live Threat

Current exploitation, exposure, and threat context

Unauthenticated attackers could bypass authorization checks in the Avada (Fusion) Builder plugin, enabling them to trigger arbitrary WordPress action hooks. This could lead to the permanent deletion of site content, denial of service, or, if vulnerable third-party handlers are present, unauthorized privileged writes to the site. The vulnerability requires a published Avada form with AJAX submission and a notification using specific field placeholders.

  • Site content and availability.
  • Invoking arbitrary action hooks.
  • Permanent content destruction.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Avada (Fusion) Builder plugin's authorization bypass vulnerability necessitates immediate action from WordPress site owners and administrators responsible for maintaining plugin integrity. The first practical step is to inventory all WordPress sites utilizing the Avada Builder, confirm if the affected plugin version is present and accessible externally, and identify the specific site owner or administrator accountable for its management. Subsequently, a risk-based remediation plan should be developed, prioritizing sites with critical business functions or sensitive data.

  • Application owners should own the issue.
  • Verify plugin presence and external accessibility.
  • Plan for immediate, coordinated remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Avada (Fusion) Builder plugin?

Avada Builder is a core component of the Avada WordPress theme ecosystem used to design and manage page layouts. It provides tools for building complex, custom-styled pages through a drag-and-drop interface and supports advanced features like AJAX-enabled forms, which allow users to submit information directly on a site without refreshing the page.

What does CWE-94 mean for CVE-2026-97670?

This CVE is classified as CWE-94, which refers to improper control of generation of code. In simple terms, the plugin fails to verify if a user has permission before executing internal WordPress actions. By manipulating specific form fields, an attacker can trick the plugin into running unintended commands, effectively letting them control site functions that should be restricted to administrators.

How is this vulnerability triggered?

An attacker triggers this by submitting data to a publicly accessible Avada form that uses AJAX. The attack succeeds if the form's notification template includes specific data placeholders that the plugin improperly parses. Note that this does not occur on forms without these notification templates, nor can it be triggered without a live, published form submission endpoint.

Who should be concerned about this vulnerability?

Anyone running an Avada-powered site with a public-facing form should be concerned. According to Halo Surface Signal, the vulnerable code exists within a form submission endpoint that is exposed by design for normal web use. Because attackers do not need to be logged in to interact with these public forms, the threat is considered external and highly reachable.

What should I do if I run this software?

Start by conducting an inventory of all WordPress installations to locate where the Avada Builder plugin is active. Once identified, verify if the site uses publicly accessible forms with notification features. Immediately coordinate with your site owners or administrative team to manage the update process, prioritizing sites that handle critical business functions or sensitive data.

References