SQL Injection, File Read Vulnerability Affect 1M Avada WordPress Sites
ID: 9edea3b0-4adf-5ac9-9bcd-c4808fe15133
STIX ID: report--9edea3b0-4adf-5ac9-9bcd-c4808fe15133
Feed Name: Cyber Press
## Executive Summary Two serious vulnerabilities in the Avada Builder WordPress plugin (CVE-2026-4798 and CVE-2026-4782), affecting versions up to 3.15.1/3.15.2 and impacting roughly 1 million active sites, allow unauthenticated time-based blind SQL injection (when WooCommerce was previously installed and then deactivated) and arbitrary server file reads via a shortcode (exploitable by Subscriber-level users), enabling credential theft, wp-config disclosure, and potential full site takeover; Avada released fixes in 3.15.3 and administrators are advised to update immediately, rotate credentials and salts, and audit for compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
