CVE-2026-54193
Deferred Deferred - Pending Action
Arbitrary File Deletion in Fusion Builder <= 3.15.4

Publication date: 2026-06-17

Last updated on: 2026-06-17

Assigner: Patchstack

Description
Contributor Arbitrary File Deletion in Fusion Builder <= 3.15.4 versions.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-17
Last Modified
2026-06-17
Generated
2026-06-17
AI Q&A
2026-06-17
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
wpbeaverbuilder fusion_builder to 3.15.4 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Compliance Impact

The provided information does not specify any direct impact of this vulnerability on compliance with common standards and regulations such as GDPR or HIPAA.

Executive Summary

The WordPress Fusion Builder Plugin versions up to and including 3.15.4 have a vulnerability that allows users with contributor or developer-level privileges to delete arbitrary files from the website.

This issue is classified as Arbitrary File Deletion and falls under the OWASP Top 10 category of Broken Access Control.

The vulnerability has a CVSS score of 7.7, indicating a moderate level of severity and potential for exploitation in widespread attacks.

Impact Analysis

This vulnerability can allow malicious actors with contributor or developer privileges to delete files from your website.

If critical or core files are deleted, it could cause your website to break or become non-functional.

Because the vulnerability can be exploited remotely over the network, it poses a significant risk to website availability and integrity.

Detection Guidance

This vulnerability affects the WordPress Fusion Builder Plugin versions up to and including 3.15.4 and involves arbitrary file deletion by users with contributor or developer-level privileges.

Detection can involve checking the installed version of the Fusion Builder plugin on your WordPress site to see if it is version 3.15.4 or earlier.

  • Use WP-CLI command to check plugin version: wp plugin list | grep fusion-builder
  • Inspect web server logs for suspicious file deletion requests or unusual activity from contributor-level accounts.
  • Monitor for unexpected file deletions or site breakage that could indicate exploitation.
Mitigation Strategies

The primary immediate mitigation step is to update the Fusion Builder plugin to version 3.15.5 or later, where the vulnerability is patched.

If updating immediately is not possible, apply the mitigation rule issued by Patchstack to block attacks targeting this vulnerability.

Additionally, restrict contributor or developer-level privileges to trusted users only and monitor for suspicious activity.

Seek assistance from your hosting provider or developers if you are unable to update or apply mitigations yourself.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-54193. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart