The Fusion Builder WordPress plugin before 3.6.2, used in...
Critical severity
Unreviewed
Published
May 17, 2022
to the GitHub Advisory Database
•
Updated Mar 24, 2024
Description
Published by the National Vulnerability Database
May 16, 2022
Published to the GitHub Advisory Database
May 17, 2022
Last updated
Mar 24, 2024
The Fusion Builder WordPress plugin before 3.6.2, used in the Avada theme, does not validate a parameter in its forms which could be used to initiate arbitrary HTTP requests. The data returned is then reflected back in the application's response. This could be used to interact with hosts on the server's local network bypassing firewalls and access control measures.
References