CVE-2026-97670 - Avada (Fusion) Builder <= 7.16.1 - Unauthenticated Arbitrary WordPress Action Invocation via '{action_hook}' Dynamic-Data Token in Form Field
CVE ID :CVE-2026-97670 Published : Oct. 10, 2026, 4:26 a.m. | 1 hour, 3 minutes ago Description :The Avada (Fusion) Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.16.1. This is due to the plugin not properly verifying authorization...