CVE-2026-6279 is a critical unauthenticated remote code execution vulnerability in the Avada Builder plugin for WordPress, also known as fusion-builder, affecting versions up to and including 3.15.2. The flaw is caused by unsafe PHP function invocation in the wp_conditional_tags branch of Fusion_Builder_Conditional_Render_Helper::get_value(), where attacker-controlled values extracted from a base64-decoded JSON structure are passed directly to call_user_func() without allowlist validation. The vulnerable code path is reachable through the fusion_get_widget_markup AJAX action, which is exposed to unauthenticated users via the non-privileged AJAX registration. Although the endpoint uses a nonce, that nonce is generated for anonymous users and is exposed in client-side JavaScript on public pages that include certain Avada components such as Post Cards or Table of Contents. An attacker can therefore obtain a valid nonce from a public page and submit crafted input that causes arbitrary PHP functions to be invoked on the server, resulting in remote code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
5 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
The repository contains one standalone 49,031-byte Python 3 exploit, CVE-2026-6279.py; it is not a framework module. It targets an alleged unauthenticated RCE condition in ThemeFusion Avada Builder through WordPress's admin-ajax.php interface. The script creates HTTP sessions with browser-like headers, normalizes target URLs, attempts HTTPS when given HTTP, scans public content for Avada nonce values using several JavaScript regular expressions, and prioritizes nonce-producing fusion_post_cards and fusion_table_of_contents shortcode contexts. The stated exploit chain submits data to the unauthenticated fusion_get_widget_markup action, which reaches render_logics and a wp_conditional_tags path that allegedly calls call_user_func without an allowlist. The CLI supports a direct single-target mode (-u and -c, with id as the default command) and an interactive menu that includes single and batch operation. Visible payload code provides Bash, Python, and netcat/FIFO reverse-shell attempts, indicating real command-execution capability rather than simple vulnerability detection. SSL certificate verification is disabled and the script includes Cloudflare IP-range recognition, likely to adjust or report target handling.
This repository is a small standalone exploit repo containing one substantial Python script and a minimal README. The main file, CVE-2026-6279.py, is an interactive exploit tool targeting CVE-2026-6279 in ThemeFusion Avada Builder <= 3.15.2 on WordPress. The script is not part of a common exploitation framework. The exploit logic is built around the vulnerability chain described in the header comments: it searches public pages for a deterministic fusion nonce, prioritizing pages likely to contain the [fusion_post_cards] or [fusion_table_of_contents] shortcodes; it then uses the unauthenticated WordPress AJAX action wp_ajax_nopriv_fusion_get_widget_markup to submit crafted data that reaches render_logics, base64/JSON decoding, and ultimately a call_user_func()-reachable code path without an allowlist. The intended outcome is unauthenticated remote code execution. Structurally, the script includes: HTTP session helpers using requests; target normalization and HTTP-to-HTTPS probing; Cloudflare IP range checks; nonce discovery using multiple regex patterns; command execution helpers; reconnaissance routines that run multiple commands and save output to a local recon_*.txt file; reverse shell helpers with several payload variants; and an interactive menu-driven main function supporting single-target and batch modes. Operationally, the exploit provides more than simple detection. It can execute arbitrary shell commands on the target and includes hardcoded reverse shell payloads: a bash /dev/tcp shell, a python3 socket-based shell, and a netcat FIFO shell using /tmp/f. Because the payloads are built in and directly usable but not highly modular, the maturity is best classified as OPERATIONAL rather than POC or fully weaponized. Notable observables include the target base URL, HTTPS probing of the site root, the vulnerable AJAX action name, nonce-related identifiers, shortcode names used for nonce discovery, temporary file paths under /tmp, and attacker callback host/port values for reverse shells.
Repository contains a single substantial Python exploit script and a short README. The script targets CVE-2026-6279 in ThemeFusion Avada Builder <= 3.15.2 on WordPress. Its stated exploit chain is: discover a deterministic public fusion_load_nonce rendered on pages using specific Avada shortcodes, then send unauthenticated requests to the WordPress AJAX handler for widget markup, abuse render_logics/base64-JSON processing, and reach a call_user_func()-style sink for remote code execution. Structurally, the script includes: HTTP/session helpers using requests; target normalization and HTTPS probing; Cloudflare-origin handling via hardcoded Cloudflare IP prefixes; nonce discovery logic using multiple regex patterns keyed to Avada JavaScript variables; command execution helpers; reconnaissance routines that run common host-enumeration commands and save output to a local recon_<target>_<time>.txt file; reverse shell helpers with bash, python3, and netcat payloads; and an interactive menu supporting single-target and batch modes. The exploit is not just a detector: it actively attempts RCE and includes multiple execution methods and post-exploitation helpers. It appears operational rather than framework-based, with hardcoded payload logic and operator-supplied targets/listener values. Fingerprintable artifacts include the Avada-specific nonce variables and shortcode markers, the unauthenticated AJAX action name, temporary file paths under /tmp, and the embedded Telegram signature URL.
Repository is a small standalone Python proof-of-concept for CVE-2026-6279 targeting ThemeFusion Avada Builder/Fusion Builder <= 3.15.2 on WordPress. Structure is minimal: one exploit script (CVE-2026-6279.py), one README describing the bug and usage, and a .gitignore. The Python script is the main entry point and implements an end-to-end unauthenticated exploitation flow: it prepares a base64-encoded JSON render_logics payload, extracts a public fusion_load_nonce from target HTML using several regex patterns, probes likely public pages/slugs for nonce leakage, and then submits POST requests to /wp-admin/admin-ajax.php with action=fusion_get_widget_markup and a chosen widget_type. The exploit tries multiple PHP functions as primitives—system, passthru, shell_exec, exec, and file_get_contents—with test arguments such as 'id' and '/etc/passwd' to confirm code execution or file read. It parses responses for uid=... evidence and handles common failure states such as expired nonce, WAF blocking, missing AJAX action, disabled PHP functions, and generic PHP errors. On success it prints the working function/widget combination and appends results to vuln.txt. Overall, this is a real exploit rather than a detector: it actively attempts remote code execution against a live web target and includes basic operational logic for target discovery, nonce extraction, exploitation retries, and result logging.
This repository is a small standalone Python proof-of-concept exploit for CVE-2026-6279 affecting Avada Builder/Fusion Builder for WordPress. The repo contains only two files: a single executable Python script (CVE-2026-6279.py) and a README describing the vulnerability, attack flow, and usage. The script is the clear entry point. Exploit flow: first, get_nonce() performs an unauthenticated GET request to the supplied target URL homepage and searches the returned HTML/JavaScript for a publicly embedded fusion_load_nonce using regex patterns. If found, exploit() builds a POST request to /wp-admin/admin-ajax.php with action=fusion_get_widget_markup and a JSON data structure containing render_logics. Inside render_logics, the script places a Base64-encoded JSON object specifying an arbitrary PHP function name and arguments. This abuses the wp_conditional_tags processing path described in the README. Main capability: unauthenticated remote code execution. The operator can supply an arbitrary OS command via --cmd; default is id. The script cycles through multiple PHP execution primitives (system, passthru, exec, shell_exec) to improve reliability. Successful exploitation is inferred from HTTP 200 responses containing command output indicators such as uid=, gid=, or the command string itself. The exploit is operational rather than a mere detector because it actively sends a malicious payload intended to execute commands on the target and display the output. It is not framework-based, not fake, and not just a README. Fingerprintable targets/endpoints are the target homepage for nonce extraction and the WordPress AJAX endpoint /wp-admin/admin-ajax.php. The exploit specifically targets vulnerable Avada Builder installations where the fusion_get_widget_markup handler accepts attacker-controlled render_logics data without restricting callable PHP functions.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An unauthenticated remote code execution vulnerability in the Avada Builder (fusion-builder) WordPress plugin caused by attacker-controlled values being passed to call_user_func() without allowlist validation, reachable via the fusion_get_widget_markup AJAX endpoint.
A critical unauthenticated remote code execution vulnerability in the Avada Builder (fusion-builder) WordPress plugin caused by unvalidated attacker-controlled function names being passed to PHP call_user_func() via a public AJAX endpoint.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.