The Avada Builder plugin for WordPress, up to version 3.15.1, contains a vulnerability allowing authenticated users to access protected post metadata. This issue arises from a failure to validate metadata key protection in the `fusion_get_post_custom_field()` function, posing a risk of exposing sensitive information even to users with minimal access rights.
We use cookies to enhance your browsing experience, serve personalized ads or content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies.