logo

SQL Injection, File Read Vulnerability Affect 1M Avada WordPress Sites

ID: 9edea3b0-4adf-5ac9-9bcd-c4808fe15133

STIX ID: report--9edea3b0-4adf-5ac9-9bcd-c4808fe15133

Feed Name: Cyber Press

Threat Score
72/100

Date Published: 2026-05-18

Date Updated: 2026-05-18

Author: Lucas Martin

...
...

## Executive Summary Two serious vulnerabilities in the Avada Builder WordPress plugin (CVE-2026-4798 and CVE-2026-4782), affecting versions up to 3.15.1/3.15.2 and impacting roughly 1 million active sites, allow unauthenticated time-based blind SQL injection (when WooCommerce was previously installed and then deactivated) and arbitrary server file reads via a shortcode (exploitable by Subscriber-level users), enabling credential theft, wp-config disclosure, and potential full site takeover; Avada released fixes in 3.15.3 and administrators are advised to update immediately, rotate credentials and salts, and audit for compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.