Input validation vulnerability in Fusion Builder 3.11.1

The Fusion Builder plugin for WordPress is vulnerable to a type of attack called Cross-Site Request Forgery. This vulnerability affects versions of the plugin up to and including 3.11.1. The problem is that it doesn’t have the right security measures in place to stop unauthenticated attackers from using third-party access tokens to change things on the website. To do so, the attacker would need to get a site administrator to click on a malicious link.

Detected in:

Avada (Fusion) Builder fixed vulnerable versions:
Fusion Builder fixed vulnerable versions: >= * <= 3.11.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.