CVE-2026-32454

WordPress Avada Core plugin < 5.15.0 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeFusion Avada Core fusion-core allows DOM-Based XSS.This issue affects Avada Core: from n/a through < 5.15.0.


We have discovered 52,812 live websites that are affected by CVE-2026-32454.

Run a Free Instant Scan




Affected Software

Product  Avada Core
Category Wordpress Plugins
Vulnerable Domains52,812 live websites (96% of Avada Core install base)
Vulnerable Versions
  • from 0 through 5.15
Vulnerable Versions Count43 versions ( 98% of all versions)



Details

  • Published - Mar 13, 2026
  • Updated - Apr 1, 2026

Credits

  • Bonds | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2026-32454
United States17,284 websites



Germany8,305 websites
GB2,834 websites
France2,765 websites
Italy2,761 websites
Netherlands2,487 websites
Spain1,725 websites
Canada1,411 websites
Switzerland1,134 websites
Australia1,085 websites

Website Distribution by TLD

Number of websites using CVE-2026-32454
.com21,501 websites
.de5,784 websites
.org3,022 websites
.nl2,308 websites
.it1,991 websites
.co.uk1,890 websites
.fr1,172 websites
.com.au1,006 websites
.ch962 websites
.net952 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-32454

Top websites that are affected by CVE-2026-32454. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*************.**.za South Africa*,***
************.com Germany**,***
*********.com United States**,***
***********.***.de Germany**,***
*************.com United States**,***
***********.com United States**,***
**********.com United States**,***
**************.org United States**,***
*****************.com Germany**,***
******.org United States**,***
See full domain list

FAQ

A total of 52,812 websites have been identified as vulnerable to CVE-2026-32454, based on global website indexing conducted by WebTechSurvey.
The Avada Core is affected by the CVE-2026-32454 vulnerability.
Avada Core versions up to and including 5.15 are vulnerable to CVE-2026-32454.