logo

Critical WordPress Plugin Bug Could Allow File Deletion Attacks on 1 Million Sites

ID: ecae0ef8-d914-55b3-b6aa-26225a848512

STIX ID: report--ecae0ef8-d914-55b3-b6aa-26225a848512

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2026-06-19

Date Updated: 2026-06-19

Author: Divya

...
...

A critical path traversal vulnerability (CVE-2026-8713, CVSS 9.1) in the Avada (Fusion) Builder WordPress plugin allows unauthenticated attackers to submit crafted form data that triggers deletion of arbitrary files (including wp-config.php), potentially enabling remote code execution and full site takeover; the issue affects versions up to 3.15.3, was patched in 3.15.4, and administrators are urged to update, audit exposed forms, and apply WAF protections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.