Input validation vulnerability in Avada (Fusion) Builder 3.12.1

The Avada (Fusion) Builder plugin, used on WordPress, can be hacked through a vulnerability known as Stored Cross-Site Scripting. This happens when the ‘fusion_map’ shortcode is used in versions 3.12.1 and below. The plugin does not properly clean and protect user inputs, which allows hackers with contributor or higher level access to insert harmful web scripts onto pages. These scripts will then run whenever someone visits the affected page.

Detected in:

Avada (Fusion) Builder fixed vulnerable versions:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.