CVE-2026-16654 | meFusion Avada Builder Plugin up to 3.15.6 on WordPress Shortcode size cross site scripting

SecurityVulns

A vulnerability classified as problematic was found in meFusion Avada Builder Plugin up to 3.15.6 on WordPress. Affected is an unknown function of the component Shortcode Handler. Such manipulation of the argument size leads to cross site scripting.

This vulnerability is traded as CVE-2026-16654. The attack may be launched remotely. There is no exploit available.VulDB Recent EntriesRead More