CVE-2026-84925 | meFusion Avada Plugin up to 7.16.1 on WordPress Multilingual set_active_language lang cross site scripting
A vulnerability labeled as problematic has been found in meFusion Avada Plugin up to 7.16.1 on WordPress. Affected by this vulnerability is the function Fusion_Multilingual::set_active_language of the component Multilingual Handler. Such manipulation of the argument lang leads to cross site scripting.
This vulnerability is referenced as CVE-2026-84925. It is possible to launch the attack remotely. No exploit is available.VulDB Recent EntriesRead More