← Vulnerability feed

Vulnerability record · CVE-2022-1386 · published 16 May 2022

CVE-2022-1386: Fusion Builder WordPress plugin SSRF via unvalidated form parameter

Fusion Builder Project · Fusion Builder

Fusion Builder, a WordPress plugin used by the Avada theme, fails to validate a parameter in its forms before version 3.6.2. This lets an attacker make the server issue arbitrary HTTP requests and reflect the responses back, enabling access to internal hosts. It matters because the plugin is widely deployed through a popular commercial theme and the flaw is remotely reachable without authentication.

9.8 CVSS 3.1 Critical EPSS 71% · top 0.6% CWE-918 · Server-side request forgery (SSRF)
9.8CVSS 3.1 base score, v2 7.5
71%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

The Fusion Builder WordPress plugin before 3.6.2, used in the Avada theme, does not validate a parameter in its forms which could be used to initiate arbitrary HTTP requests. The data returned is then reflected back in the application's response. This could be used to interact with hosts on the server's local network bypassing firewalls and access control measures.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or interaction required, very high EPSS, and public exploit references make this an urgent patch.

What it is

Fusion Builder, a WordPress plugin used by the Avada theme, fails to validate a parameter in its forms before version 3.6.2. This lets an attacker make the server issue arbitrary HTTP requests and reflect the responses back, enabling access to internal hosts. It matters because the plugin is widely deployed through a popular commercial theme and the flaw is remotely reachable without authentication.

Impact

An attacker can use the server as a proxy to reach hosts on its local network, bypassing firewalls and access controls, and read the reflected responses. This can expose internal services and data that are not otherwise reachable from the internet.

Attack surface

Reached over the network through the plugin's form handling; the CVSS vector shows no privileges or user interaction required. Any exposed WordPress site running the affected plugin is a candidate target.

Exploitation

Not listed in CISA KEV, but EPSS is 0.71427 (99.4th percentile) and references include an Exploit-tagged WPScan entry, indicating public exploit information exists. No ransomware association is documented.

What to do

  • Update Fusion Builder to 3.6.2 or later (Avada 7.6.2 security update) immediately.
  • If patching is delayed, disable or remove the Fusion Builder plugin until it can be updated.
  • Restrict outbound network access from the web server to internal ranges where feasible.
  • Place the WordPress site behind a WAF and block requests that attempt to supply external URLs to form parameters.
  • Audit the server for signs of internal scanning or unexpected outbound requests.

Detection

  • Monitor web server and application logs for form submissions containing URL-like values in Fusion Builder parameters.
  • Alert on outbound HTTP requests originating from the web server to internal RFC1918 addresses or localhost.
  • Review responses for reflected content from internal services returned to clients.
  • Check for unexpected network connections from the WordPress host to non-standard internal ports.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-1386 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-13346Theme-fusion avada code injection vulnerabilityThe Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and…EPSS 2.3%8.8CVE-2023-39312Theme-fusion avada missing authorization vulnerabilityMissing Authorization vulnerability in ThemeFusion Avada.This issue affects Avada: from n/a through 7.11.1.EPSS 0.60%8.8CVE-2023-39922Theme-fusion avada missing authorization vulnerabilityMissing Authorization vulnerability in ThemeFusion Avada.This issue affects Avada: from n/a through 7.11.1.EPSS 0.37%8.8CVE-2023-39307Theme-fusion avada unrestricted file upload vulnerabilityUnrestricted Upload of File with Dangerous Type vulnerability in ThemeFusion Avada.This issue affects Avada: from n/a through 7.11.1.EPSS 0.67%8.8CVE-2024-1468Theme-fusion avada unrestricted file upload vulnerabilityThe Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validati…EPSS 1.2%8.8CVE-2022-41996Theme-fusion avada cross-site request forgery vulnerabilityCross-Site Request Forgery (CSRF) vulnerability in ThemeFusion Avada premium theme versions <= 7.8.1 on WordPress leading to arbitrary plugin install…EPSS 0.50%8.8CVE-2017-18607Theme-fusion avada cross-site request forgery vulnerabilityThe avada theme before 5.1.5 for WordPress has CSRF.EPSS 0.67%7.7CVE-2023-39313Theme-fusion avada server-side request forgery (ssrf) vulnerabilityServer-Side Request Forgery (SSRF) vulnerability in ThemeFusion Avada.This issue affects Avada: from n/a through 7.11.1.EPSS 0.57%

Source: NIST National Vulnerability Database (record CVE-2022-1386), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.