CVE-2026-32454 | ThemeFusion Avada Core Plugin up to 5.15.0 on WordPress cross site scripting (EUVD-2026-12007)
A vulnerability was found in ThemeFusion Avada Core Plugin up to 5.15.0 on WordPress. It has been rated as problematic. The impacted element is an unknown function. Performing a manipulation results in cross site scripting.
This vulnerability was named CVE-2026-32454. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is advised.