logo

1M WordPress Sites at Risk: Critical Unauthenticated Arbitrary File Deletion in Avada Builder (CVSS 9.1)

ID: c6693fc9-84e2-58dc-9d0a-e55c93f7058d

STIX ID: report--c6693fc9-84e2-58dc-9d0a-e55c93f7058d

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-06-19

Date Updated: 2026-06-19

Author: Do Son

...
...

A critical unauthenticated arbitrary file deletion vulnerability (CVE-2026-8713, CVSS 9.1) in Avada (Fusion) Builder <= 3.15.3 allows attackers to perform path-traversal deletions (including wp-config.php) via form entry cleanup, potentially enabling full site takeover; Avada Builder 3.15.4 contains the fix and administrators should update immediately (approximately 1,000,000 sites may be affected; no confirmed mass exploitation reported).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.