1M WordPress Sites at Risk: Critical Unauthenticated Arbitrary File Deletion in Avada Builder (CVSS 9.1)
ID: c6693fc9-84e2-58dc-9d0a-e55c93f7058d
STIX ID: report--c6693fc9-84e2-58dc-9d0a-e55c93f7058d
Feed Name: securityonline.info
Threat Score
A critical unauthenticated arbitrary file deletion vulnerability (CVE-2026-8713, CVSS 9.1) in Avada (Fusion) Builder <= 3.15.3 allows attackers to perform path-traversal deletions (including wp-config.php) via form entry cleanup, potentially enabling full site takeover; Avada Builder 3.15.4 contains the fix and administrators should update immediately (approximately 1,000,000 sites may be affected; no confirmed mass exploitation reported).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
