CVE-2025-49940

WordPress Fusion Builder plugin <= 3.13.2 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeFusion Fusion Builder fusion-builder allows DOM-Based XSS.This issue affects Fusion Builder: from n/a through <= 3.13.2.


We have discovered 113,507 live websites that are affected by CVE-2025-49940.

Run a Free Instant Scan




Affected Software

Product  Avada Builder
Category Wordpress Plugins
Vulnerable Domains113,507 live websites (48% of Avada Builder install base)
Vulnerable Versions
  • from 0 through 3.13.2
Vulnerable Versions Count50 versions ( 83% of all versions)



Details

  • Published - Oct 22, 2025
  • Updated - Apr 28, 2026

Credits

  • João Pedro S Alcântara (Kinorth) | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2025-49940
United States28,915 websites



Germany17,394 websites
Italy6,987 websites
GB6,404 websites
France5,908 websites
Netherlands5,082 websites
Spain4,625 websites
Canada2,612 websites
Australia2,430 websites
Switzerland2,119 websites

Website Distribution by TLD

Number of websites using CVE-2025-49940
.com42,871 websites
.de11,904 websites
.it4,956 websites
.org4,727 websites
.nl4,672 websites
.co.uk4,030 websites
.fr2,423 websites
.com.au2,225 websites
.net1,994 websites
.es1,961 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-49940

Top websites that are affected by CVE-2025-49940. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*************.**.za South Africa*,***
****.com Russia**,***
************.com Bulgaria**,***
********.at United States**,***
******************.org United States**,***
****.org United States**,***
*************.com United States**,***
***********.com United States**,***
*********.com United States**,***
******************.com United States**,***
See full domain list

FAQ

A total of 113,507 websites have been identified as vulnerable to CVE-2025-49940, based on global website indexing conducted by WebTechSurvey.
The Avada Builder is affected by the CVE-2025-49940 vulnerability.
Avada Builder versions up to and including 3.13.2 are vulnerable to CVE-2025-49940.