#VU27492 Permissions, Privileges, and Access Controls in Avada
Published: May 4, 2020
Avada
ThemeFusion
Description
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to improper permissions checks in the "fusion_builder_save_layout" AJAX action used to call the "save_layout" function. A remote authenticated attacker can create a post, select several parameters (post type, post status, slug etc), as well as inject JavaScript code with the [fusion_code] attribute.