logo

1 Million WordPress Sites Affected by Avada Builder File Read and SQL Injection Flaws

ID: 92c1a7b5-49c2-56b0-89b6-f4dcca7edfe7

STIX ID: report--92c1a7b5-49c2-56b0-89b6-f4dcca7edfe7

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-05-18

Date Updated: 2026-05-19

Author: Abinaya

...
...

Two vulnerabilities were disclosed in the Avada Builder WordPress plugin (CVE-2026-4782: arbitrary file read; CVE-2026-4798: time-based SQL injection) affecting versions up to 3.15.2/3.15.1, potentially exposing wp-config.php and enabling extraction of user credentials. Avada released fixes ending in version 3.15.3 (12 May 2026); site owners are advised to update immediately, audit user roles, monitor logs, and deploy a web application firewall.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.