PT-2026-25297 · Themefusion · Avada Core

Bonds

·

Published

2026-03-13

·

Updated

2026-03-14

·

CVE-2026-32453

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions ThemeFusion Avada Core versions prior to 5.15.0
Description A missing authorization check exists in ThemeFusion Avada Core fusion-core, allowing exploitation of incorrectly configured access control security levels. The issue allows unauthorized access due to improperly set security controls.
Recommendations Update ThemeFusion Avada Core to version 5.15.0 or later.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-32453

Affected Products

Avada Core