1 Million WordPress Sites Affected by Avada Builder File Read and SQL Injection Flaws
ID: 92c1a7b5-49c2-56b0-89b6-f4dcca7edfe7
STIX ID: report--92c1a7b5-49c2-56b0-89b6-f4dcca7edfe7
Feed Name: cybersecurityNews.com
Threat Score
Two vulnerabilities were disclosed in the Avada Builder WordPress plugin (CVE-2026-4782: arbitrary file read; CVE-2026-4798: time-based SQL injection) affecting versions up to 3.15.2/3.15.1, potentially exposing wp-config.php and enabling extraction of user credentials. Avada released fixes ending in version 3.15.3 (12 May 2026); site owners are advised to update immediately, audit user roles, monitor logs, and deploy a web application firewall.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
