← back
CVE-2022-1386observed exploitationCWE-918

Fusion Builder < 3.6.2 - Unauthenticated SSRF

82Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 72%
from disclosure to weapon288 days
Published on NVDMay 16
1st PoC+288d
VulnCheck+596d
exploitation probability
72%top 1% of all CVEs
observed exploitation
yesVulnCheck
6 public exploit(s)
The Fusion Builder WordPress plugin before 3.6.2, used in the Avada theme, does not validate a parameter in its forms which could be used to initiate arbitrary HTTP requests. The data returned is then reflected back in the application's response. This could be used to interact with hosts on the server's local network bypassing firewalls and access control measures.
Affected products
Unknown · Fusion Builder
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.