Critical WordPress Plugin Bug Could Allow File Deletion Attacks on 1 Million Sites
ID: ecae0ef8-d914-55b3-b6aa-26225a848512
STIX ID: report--ecae0ef8-d914-55b3-b6aa-26225a848512
Feed Name: GBHackers
Threat Score
A critical path traversal vulnerability (CVE-2026-8713, CVSS 9.1) in the Avada (Fusion) Builder WordPress plugin allows unauthenticated attackers to submit crafted form data that triggers deletion of arbitrary files (including wp-config.php), potentially enabling remote code execution and full site takeover; the issue affects versions up to 3.15.3, was patched in 3.15.4, and administrators are urged to update, audit exposed forms, and apply WAF protections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
