Critical WordPress Plugin Vulnerability Exposes 1 Million Sites to File Deletion Attacks
ID: d902553a-429a-5513-af1c-3354677b93bd
STIX ID: report--d902553a-429a-5513-af1c-3354677b93bd
Feed Name: cybersecurityNews.com
Threat Score
**Critical Avada (Fusion) Builder vulnerability (CVE-2026-8713)** — A path-traversal flaw in the plugin’s maybe_delete_files() logic lets unauthenticated attackers submit crafted form data to delete arbitrary files (e.g., wp-config.php), which can force site setup and enable full takeover and RCE; the issue (CVSS 9.1) affects versions up to 3.15.3 and was patched in 3.15.4, with Wordfence providing firewall detection for malicious form submissions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
