MEDIUM (6.4)
    Plugin

    Sensitive Information Exposure in Avada Builder Plugin via Unprotected Metadata Keys

    Published Date: 4/15/2026
    CVE ID: CVE-2026-1541

    Summary

    The Avada Builder plugin for WordPress, up to version 3.15.1, contains a vulnerability allowing authenticated users to access protected post metadata. This issue arises from a failure to validate metadata key protection in the `fusion_get_post_custom_field()` function, posing a risk of exposing sensitive information even to users with minimal access rights.

    Vulnerability Details

    The vulnerability in the Avada Builder plugin stems from a lack of verification for metadata keys, specifically those prefixed with an underscore, which are intended to be protected from general view. The function `fusion_get_post_custom_field()` is responsible for managing dynamic data within posts, and its current implementation neglects to restrict access to these protected fields for authenticated users, such as subscribers. The flaw allows such users to potentially retrieve sensitive information, which could lead to privacy breaches or unauthorized information disclosure. This exposure is particularly concerning in a multi-user environment where least privilege principles are expected to be upheld. The potential impacts include unauthorized data access and potential financial or reputational damage if sensitive data leaks are exploited maliciously.

    Recommendations

    To mitigate this vulnerability, implement checks within the `fusion_get_post_custom_field()` function to ensure metadata keys with underscore prefixes are not accessible. Educate users about access controls and limit user roles to only those necessary for their responsibilities. Regularly review and audit user permissions and plugin configurations to enhance security.

    Available Fixes

    Last Updated: 4/16/2026
    Jedar

    Jedar for Digital Rights is a non-profit organization dedicated to protecting digital freedoms, enhancing online privacy, and promoting secure digital practices for vulnerable communities worldwide.

    Follow Us

    All Rights Reserved © 2026 Jedar for Digital Rights.

    Cookie Preferences

    We use cookies to enhance your browsing experience, serve personalized ads or content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies.

    Learn More