CVE-2026-4782: stato di sfruttamento e disponibilità della patch

CVE-2026-4782 · CVSS 6.5 MEDIUM · EPSS <1%

The Avada Builder plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.15.2 via the 'fusion_get_svg_from_file' function with the 'custom_svg' parameter of the 'fusion_section_separator' shortcode. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. The vulnerability was partially patched in version 3.15.2 and fully patched in version 3.15.3.

CVE-2026-4782 viene sfruttato?

Quali prodotti e versioni sono interessati?

Nessun elenco di pacchetti interessati registrato qui.

Esiste una patch?

Nessun identificativo di patch registrato qui.

Cosa ha pubblicato PlainSec su CVE-2026-4782

Fonti primarie

Cosa questa scheda non dice

KEV ed EPSS vengono ricontrollati ogni giorno. Scheda aggiornata il 2026-08-11.