logo

Critical WordPress Plugin Vulnerability Exposes 1 Million Sites to File Deletion Attacks

ID: d902553a-429a-5513-af1c-3354677b93bd

STIX ID: report--d902553a-429a-5513-af1c-3354677b93bd

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-06-19

Date Updated: 2026-06-20

Author: Abinaya

...
...

**Critical Avada (Fusion) Builder vulnerability (CVE-2026-8713)** — A path-traversal flaw in the plugin’s maybe_delete_files() logic lets unauthenticated attackers submit crafted form data to delete arbitrary files (e.g., wp-config.php), which can force site setup and enable full takeover and RCE; the issue (CVSS 9.1) affects versions up to 3.15.3 and was patched in 3.15.4, with Wordfence providing firewall detection for malicious form submissions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.