PT-2026-25295 · Themefusion · Fusion Builder
Bonds
·
Published
2026-03-13
·
Updated
2026-03-14
·
CVE-2026-32451
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ThemeFusion Fusion Builder versions prior to 3.15.0
Description
A missing authorization issue exists in ThemeFusion Fusion Builder, allowing exploitation of incorrectly configured access control security levels. The issue allows unauthorized access due to improper configuration of access controls.
Recommendations
Update ThemeFusion Fusion Builder to version 3.15.0 or later.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fusion Builder