S4E just found a low dns any record query
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-1386 Scanner

CVE-2022-1386 scanner - Server-Side Request Forgery (SSRF) vulnerability in Fusion Builder plugin for Wordpress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-1386
9.8
CVSS

The Fusion Builder WordPress plugin before 3.6.2, used in the Avada theme, does not validate a parameter in its forms which could be used to initiate arbitrary HTTP requests. The data returned is then reflected back in the application's response. This could be used to interact with hosts on the server's local network bypassing firewalls and access control measures.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Fusion Builder
AFFECTED< 3.6.2SAFE ✓≥ 3.6.2
Updated Aug 22, 2026View on NVD →
Detail

The Fusion Builder plugin for WordPress is one of the most popular page builders, used by website owners to design and create beautiful pages without dealing with complex coding. It is a product of Avada Themes, a company that offers a range of premium themes and plugins for WordPress users. This plugin is easy to use, intuitive, and comes with many customization options, making it a preferred choice for designers and developers.

However, in recent times, a severe vulnerability was discovered in the Fusion Builder plugin. Identified as CVE-2022-1386, this vulnerability is caused by a lack of validation of a parameter in its forms, which could enable attackers to initiate arbitrary HTTP requests, obtaining and controlling the data returned in the application's response. Hackers can use this vulnerability to gain access to servers on the local network, bypassing firewalls and other access control measures.

The potential consequences of exploiting this vulnerability are significant and could lead to data loss, server hijacking, and network infiltration. Attackers can use the compromised server to launch further cyber-attacks, such as malware distribution or phishing campaigns. The Fusion Builder plugin vulnerability is a severe threat to the security of WordPress websites and their users.

s4e.io is a comprehensive security platform that provides information about vulnerabilities in digital assets. With its Pro features, users can quickly and easily learn about vulnerabilities, receive alerts when new vulnerabilities are detected, and carry out in-depth analysis of their sites to identify potential risks. By signing up for s4e.io, website owners can protect their digital assets from cyber-attacks, data loss, and network infiltration. Don't wait until it's too late to protect your website and its users; sign up today.

 

REFERENCES

Solution Advice

To protect against this vulnerability, it is necessary to follow best practices and implement the following precautions:

  • Keep all WordPress plugins and themes updated regularly
  • Use a firewall to monitor and block suspicious traffic
  • Install a reputable security plugin and ensure it's up-to-date
  • Implement two-factor authentication for all user accounts, including administrators
  • Be vigilant with security measures, including strong passwords and limited access to sensitive data.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.