logo

Avada Builder WordPress plugin flaws allow site credential theft

ID: d04c7890-16e9-5545-b0ce-41439292d6fa

STIX ID: report--d04c7890-16e9-5545-b0ce-41439292d6fa

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2026-05-15

Date Updated: 2026-05-15

Author: Bill Toulas

...
...

**Avada Builder vulnerabilities (CVE-2026-4782 & CVE-2026-4798):** Two serious flaws in the Avada Builder WordPress plugin—an authenticated arbitrary file read allowing access to sensitive files like wp-config.php, and a time-based blind SQL injection exploitable under specific WooCommerce conditions—affect roughly one million active installs; partial and full fixes were released (3.15.2 and 3.15.3) and site owners are advised to upgrade to 3.15.3 immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.